# Plumber Platform Source: https://getplumber.io/docs/getting-started Get started with the Plumber Platform: connect GitHub or GitLab, audit your CI/CD pipelines for security gaps, and remediate drift continuously. Plumber is a CI/CD security platform that continuously maps, audits, and remediates security gaps in your GitHub Actions workflows and GitLab CI/CD pipelines, so you stay ready for ISO 27001, NIS2, DORA, and SOC 2 audits. ## Secure Your CI/CD Pipelines **CI/CD pipelines are the backbone of your software supply chain, and ensuring their security is a challenging and time-consuming task. Plumber automates this process for you.** - Your CI/CD mapped and fully monitored - 90% less manual effort to keep CI/CD secure - Always audit-ready ## Quick Installation Guide
Scope
GitHub Actions support is currently Open Source CLI only.
All controls below carry the
What Plumber scans (GitHub CLI)
.github/workflows/ in the analyzed ref (local clone or remote fetch).$GITHUB_ENV writes, no evaluation of GitHub expression syntax in values.uses: third-party owner/repo@ref actions (ISSUE-702/703). Not local ./.github/actions/*, not job-level reusable-workflow uses:, not nested actions inside composites.gh auth login or GH_TOKEN. Without auth they abstain (no finding, not a pass).Severity
Impact if the issue is present and exploited, not likelihood. Plumber detects; you assess.
Fix duration
Rough effort to remediate. Your environment and process may differ.
analyze flag, the config commands, exit codes, and the JSON / PBOM / CycloneDX output.ISSUE-XXX with severity, impact, and remediation.include: that runs on every pipeline (no binary to install) with MR comments, project badges, and a live score badge.analyze flag, the config commands, exit codes, and the JSON / PBOM / CycloneDX output.ISSUE-XXX with severity, impact, and remediation.