惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
N
Netflix TechBlog - Medium
P
Proofpoint News Feed
D
Docker
J
Java Code Geeks
L
LangChain Blog
Microsoft Security Blog
Microsoft Security Blog
The GitHub Blog
The GitHub Blog
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
云风的 BLOG
云风的 BLOG
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
月光博客
月光博客
T
Tailwind CSS Blog
M
MIT News - Artificial intelligence
Blog — PlanetScale
Blog — PlanetScale
Google DeepMind News
Google DeepMind News
腾讯CDC
罗磊的独立博客
U
Unit 42
爱范儿
爱范儿
Vercel News
Vercel News
MyScale Blog
MyScale Blog

Step Security Blog

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity Top 2024 Predictions for CI/CD Security - StepSecurity Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity 10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity 2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity
StepSecurity Is Sponsoring GitHub Universe 2025 - StepSec...
2025-10-08 · via Step Security Blog

GitHub Universe is where the global developer community comes together to learn, share, and explore the future of software development. From product announcements to hands-on workshops, it’s the stage where innovation in DevOps, AI, and open source takes center stage.

At StepSecurity, our mission is to make GitHub Actions workflows secure by default. That’s why we’re thrilled to announce that we are a Bronze Sponsor of GitHub Universe 2025.

📅 When: October 28–29, 2025

📍 Where: Fort Mason Center, San Francisco, Booth #102

Why GitHub Universe Matters

CI/CD pipelines are the backbone of modern software delivery — but they’re also an increasingly common target for supply chain attacks. With GitHub Actions at the heart of countless development workflows, securing these pipelines isn't optional anymore — it's critical.

GitHub Universe is the perfect venue for us to highlight solutions that protect developers from workflow misconfigurations, compromised actions, and secrets exfiltration risks. By sponsoring this event, we’re investing directly in the developer community that depends on GitHub Actions every day.

Experience StepSecurity in Action

Stop by Booth #102 to see how we're revolutionizing GitHub Actions security:

  • Real-world threat detection: Watch how StepSecurity Harden-Runner caught the tj-actions/changed-files incident in real-time through baseline monitoring of outbound network calls
  • Third-party actions governance: Evaluate risks from 3rd party actions and discover our secure, drop-in replacements for risky actions
  • Policy enforcement: See automated workflow blocking in action when security standards aren't met

What You'll Take Away

  • Best practices for hardening GitHub Actions workflows against emerging threats
  • Hands-on guidance for implementing security guardrails in your pipelines
  • Awesome swag to remember us by! 🎁

Connect with our team to discuss how we can help you implement guardrails and block risky automation in your pipelines.

Can't Make It? We've Got You Covered

Enter our raffle for FREE and discounted passes! We're giving away tickets to GitHub Universe 2025. Simply fill out this form before October 13th for your chance to join us.

Join the Movement

We’re proud to stand alongside GitHub and the developer community at Universe 2025. Whether you’re attending in person or online, we invite you to join us in shaping a more secure future for CI/CD.

See you at GitHub Universe!