StepSecurity
@step_security
Followers
176
Following
87
Media
16
Statuses
176
Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner
Joined November 2021
📢 Press release of our GitHub Actions Security Platform! While many of you are already familiar with its prowess — given its adoption by over 1,200 open-source projects and numerous enterprises — today, we formally put it in the spotlight. https://t.co/e3YFOFZ34v
prnewswire.com
/PRNewswire/ -- StepSecurity, a leader in CI/CD Security, has announced the launch of its GitHub Actions Security Platform to counter escalating cyber threats...
0
2
6
5/5 This is the second CI/CD supply chain attack detected by Harden-Runner in 2024. Earlier, it caught an exploit in Google’s open-source project, Flank. Check out the full case study and video of the Azure Karpenter project for all the details:
stepsecurity.io
This case study discusses how StepSecurity Harden-Runner detected a CI/CD supply chain attack in real-time in Microsoft’s open-source project Azure Karpenter Provider
0
0
2
4/5 We’re honored to be recognized on Microsoft’s acknowledgment portal for our contribution to securing their online services. Following this exploit, the repository now uses Harden-Runner in block mode, preventing unauthorized outbound calls that aren't on the allowed list.🙌
1
0
1
3/5 This anomaly triggered Harden-Runner’s real-time detection alert. Within just an hour of the exploit, StepSecurity reported it to the Microsoft Security Response Center (MSRC).
1
0
0
2/5 Harden-Runner established a baseline of outbound network calls for the impacted job after hundreds of runs. When a researcher exploited a vulnerability to exfiltrate a secret, the call went to a domain outside the baseline. ⚠️
1
0
0
1/5 All #GitHub Actions workflows in the @Microsoft Azure Karpenter Provider project have been secured with StepSecurity’s Harden-Runner since January 2024. Here's how Harden-Runner detected a potential supply chain attack in real-time. 👇
1
2
9
& ease of integrating third-party tools directly from the GitHub Actions Marketplace. 📢We've just published a blog post on migrating from Jenkins to #GitHub Actions. If you're considering making the switch, check out our latest blog:
0
0
0
❗Several of our enterprise customers adopted StepSecurity when they were migrating from Jenkins to GitHub Actions. In our conversations, we’ve noticed many enterprises are making the move from #Jenkins to #GitHubActions for its streamlined workflows, robust #security features..
1
2
3
🛠️ Our latest blog post covers everything you need to know about pinning, like: ✅Why you need to pin GitHub Actions ✅Guide to manually pin GitHub Actions ✅Best practices for pinning ✅Challenges, solutions & tools for pinning ✅ Automatic pinning with StepSecurity
1
0
0
🛡️ To avoid this risk, you need to pin actions to an immutable reference – like the full-length commit SHA. This guarantees that your workflows always use a specific, unchangeable version of the action, preventing unauthorized updates and ensuring consistent security.
1
0
0
⚠️Malicious actors can inject harmful code into your CI/CD pipelines by updating action versions with malicious code, leading to the theft of sensitive information like API keys and cloud admin credentials.
1
0
0
🔒 Did you know unpinned actions can lead to security risks in your GitHub workflows? Unpinned #GitHub Actions expose your workflows to vulnerabilities and #supplychainattacks.
1
0
1
🛡️ Enhancing #OSSSecurity can be complex and time-consuming. @step_security's Secure-Repo automates critical best practices, streamlining the process for maintainers to improve their projects' security posture efficiently. Learn more: https://t.co/VVK5hY58pN
0
4
5
Here’s what you can expect: 1️⃣Introduction to XZ Utils Build Process 2️⃣XZ Live Analysis of XZ Utils Build Process with Harden-Runner 3️⃣Understanding the Importance of Runtime Security Monitoring to Identify Supply Chain Attacks
0
0
0
Live Analysis of Backdoored XZ Utils Build Process with StepSecurity Harden-Runner 📅Date & Time: May 22nd 2024, 9:30 am Pacific Time ➡️Register here:
1
1
1
We're thrilled to announce @step_security joining OpenSSF! 👏 StepSecurity offers a platform that secures CI/CD infrastructure and pipelines against security attacks, trusted by over 2700 open source projects that use GitHub Actions. 💻
0
4
12
🎉We are thrilled to announce that StepSecurity has secured $3 million in seed #funding to protect CI/CD pipelines for open-source communities and enterprises!
stepsecurity.io
StepSecurity secures $3M seed funding to revolutionize CI/CD pipeline security. Learn about our mission, unique approach, and roadmap to protect open-source and enterprise CI/CD environments.
0
3
8
🎉Our partnership with OpenSSF has been fantastic so far, & formalizing it will allow us to empower even more open source maintainers to protect their projects against CI/CD attacks. Read more about this partnership here: https://t.co/pFxhwQa0gb & here:
stepsecurity.io
StepSecurity has joined the Open Source Security Foundation (OpenSSF)! Learn how this collaboration strengthens our mission to enhance open-source software security and protect CI/CD pipelines.
0
0
0
🤝StepSecurity has already collaborated with OpenSSF Scorecard, and our automation has helped hundreds of open source maintainers to achieve higher scores.
1
0
0