惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
人人都是产品经理
人人都是产品经理
V
V2EX
量子位
Last Week in AI
Last Week in AI
Jina AI
Jina AI
博客园 - 【当耐特】
爱范儿
爱范儿
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
博客园 - 三生石上(FineUI控件)
有赞技术团队
有赞技术团队
小众软件
小众软件
IT之家
IT之家
博客园_首页
博客园 - 聂微东
S
SegmentFault 最新的问题
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗

Step Security Blog

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity Top 2024 Predictions for CI/CD Security - StepSecurity Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity 10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity 2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity
Announcing StepSecurity’s Integration with RunsOn: Secure...
2025-07-08 · via Step Security Blog

We’re excited to announce our integration with RunsOn, the modern way to self-host GitHub Actions runners at scale on AWS, with incredible cost savings and advanced features. With this partnership, StepSecurity Harden-Runner now seamlessly integrates with RunsOn, providing enhanced security and visibility for CI/CD pipelines.

Why This Integration Matters

As software supply chain attacks continue to rise, securing your CI/CD environment is more critical than ever. Harden-Runner protects against supply chain threats by restricting outbound network calls, monitoring runtime activity, and providing actionable insights—all without disrupting developer workflows. By integrating with RunsOn, teams can now benefit from these security enhancements while leveraging RunsOn’s optimized, scalable, and cost-efficient CI/CD runners.

This integration eliminates all deployment friction with Harden-Runner as it comes preinstalled in RunsOn StepSecurity images, ensuring you achieve 100% coverage from day one.

Why Choose RunsOn?

RunsOn offers a powerful alternative to GitHub-hosted runners, delivering:

  1. 10x cheaper costs than GitHub-hosted runners
  1. At least 30% faster performance compared to GitHub-hosted runners
  1. 5x faster, unlimited caching with an S3-local bucket
  1. Fully self-hosted in your own AWS account
  1. No concurrency limits

Key Benefits of the Integration

- Comprehensive CI/CD Security: Harden-Runner ensures that every build running on RunsOn adheres to strict security controls, preventing unauthorized outbound network calls and detecting suspicious behaviors in real time.

- Seamless Deployment: RunsOn customers can use out of the box StepSecurity-provided images with their RunsOn deployment. This allows them to use the latest Harden-Runner agent without manually baking it into their CI/CD images and without the hassle of updating the agent when a new version becomes available.

- Minimal Setup: Just use the Runs-On StepSecurity images and start benefiting from security insights without additional manual configuration.

Getting Started

Example Workflow

To use StepSecurity Harden-Runner with RunsOn, simply update your runner configuration to use a StepSecurity image. Here's an example GitHub Actions workflow:  

jobs:
  build:
    runs-on: 
      - runs-on=${{ github.run_id }} 
      - runner=2cpu-linux-x64 
      - image=ubuntu24-stepsecurity-x64 

This setup ensures that you are always using the latest Harden-Runner agent without manually baking it into your image or handling updates yourself.

Enabling StepSecurity’s Harden-Runner on RunsOn is simple. Follow our integration guide to set up Harden-Runner within your RunsOn-powered workflows. Once integrated, you’ll have complete visibility into network and runtime activity while maintaining full control over your build security.

Looking Ahead

At StepSecurity, we’re committed to making CI/CD security accessible, effective, and developer-friendly. Our partnership with RunsOn is another step toward ensuring that organizations can secure their software supply chains without compromising agility or performance.

Try out the integration today and let us know your feedback! If you have any questions, contact us.