惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

宝玉的分享
宝玉的分享
T
The Blog of Author Tim Ferriss
Engineering at Meta
Engineering at Meta
博客园 - 叶小钗
T
Tailwind CSS Blog
博客园 - Franky
WordPress大学
WordPress大学
博客园 - 司徒正美
D
DataBreaches.Net
L
LangChain Blog
G
Google Developers Blog
C
Check Point Blog
爱范儿
爱范儿
阮一峰的网络日志
阮一峰的网络日志
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
S
SegmentFault 最新的问题
Microsoft Security Blog
Microsoft Security Blog
J
Java Code Geeks
美团技术团队
腾讯CDC
Martin Fowler
Martin Fowler
博客园 - 聂微东
MongoDB | Blog
MongoDB | Blog
Jina AI
Jina AI

Step Security Blog

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity Top 2024 Predictions for CI/CD Security - StepSecurity Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity 10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity 2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity
StepSecurity Steps Up the Security Game with SOC 2 Type 2...
2025-07-08 · via Step Security Blog

We are thrilled to share that StepSecurity has achieved SOC 2 Type 2 compliance certification. This certification recognizes our commitment to providing the highest level of security for our customers' data and systems.  

As a cloud-based security company, we understand the importance of implementing strong security and privacy controls to protect our customers. Achieving SOC 2 Type 2 compliance is a rigorous and comprehensive process that requires organizations to meet strict security and privacy standards. We are proud to say that we have passed this process with flying colors, without any exceptions for mandatory security controls.  

The StepSecurity platform enables several mandatory SOC 2 controls such as dependabot via auto remediation pull requests. We ourselves use the platform to guarantee that all crucial repositories have mandatory security tools enabled. At StepSecurity, security is not an afterthought but a core principle that we incorporate into everything we do. We have always taken a secure-by-default approach to building our services, and we embrace the "assume breach" mindset. We have deployed multiple security controls across our SDLC to provide comprehensive security protection, and we follow the principles of least privilege to ensure that our designs only provide services with the minimal access required to customer code and data.

Public Repositories

The StepSecurity platform does not require any credentials or explicit onboarding before it can analyze public repositories and provide automated security remediations. Harden-Runner also does not require any GitHub privileges to protect CI/CD for public repositories.  

Private Repositories

The StepSecurity Platform supports an outpost deployment, which processes customer code in a customer controller environment without giving StepSecurity access to source code or CI/CD pipeline definitions. Harden-Runner only requires access to build logs, and does not require direct access to proprietary source code or CI/CD pipeline definitions.

We understand the importance of safeguarding our customers' data, and we take all necessary precautions to ensure customer data is secure. If you are an enterprise customer interested in using our services, we are happy to provide you with our SOC 2 Type 2 report upon request.