惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
V
Visual Studio Blog
雷峰网
雷峰网
J
Java Code Geeks
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog RSS Feed
C
Check Point Blog
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
V
V2EX
D
Docker
IT之家
IT之家
博客园 - 聂微东
腾讯CDC
U
Unit 42
Microsoft Security Blog
Microsoft Security Blog
The Cloudflare Blog

Step Security Blog

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity Top 2024 Predictions for CI/CD Security - StepSecurity Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity 10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity 2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity
Replace Third-Party Actions with StepSecurity Maintained ...
2025-07-08 · via Step Security Blog

We've been helping our customers secure their CI/CD pipelines with StepSecurity Maintained Actions and Policy Driven PRs for automated security fixes.  

But there was one manual step remaining - replacing risky third-party Actions with StepSecurity's secure drop-in replacement actions required tedious, repo-by-repo updates.  

Today, we're thrilled to announce that Policy Driven PRs now automate the replacement of third-party GitHub Actions with StepSecurity Maintained Actions across your entire organization.

Why This Matters

Before diving into how it works, let’s first look at what StepSecurity Maintained Actions are and why they’re a game-changer for securing your CI/CD pipelines.

What Are StepSecurity Maintained Actions?

StepSecurity Maintained Actions are a curated set of trusted GitHub Actions maintained by our security engineering team. They are designed to reduce the risk of supply chain attacks caused by compromised third-party actions, while also enhancing security, reliability, and consistency across workflows.

Why We Maintain These Actions

We onboard actions based on enterprise customer demand, especially when they:

  • Have been abandoned by the original maintainers
  • Are maintained by a single developer
  • Receive low security scores (based on OpenSSF ScoreCard)
  • Require elevated permissions (like access to repository secrets), which could increase security risk

Case Study Comparisons

To understand the importance of these mitigations, let’s look at two recent real-world security incidents involving GitHub Actions:

  • tj-actions/changed-files: A compromise occurred when a persistent bot account with repository access was exploited to update tags.  

StepSecurity actions eliminate this risk by avoiding persistent credentials and requiring environment-based approvals for releases.

  • reviewdog actions: Security was compromised due to overly permissive access control where contributors who submitted to reviewdog/action-* repositories were automatically invited to the reviewdog/actions-maintainer team, which had write access to these repositories.  

StepSecurity restricts access exclusively to our dedicated maintenance team.

Automate Secure Replacements with Policy Driven PRs

Even when a secure StepSecurity Maintained Action exists, updating every workflow manually across all your repos is tedious and error-prone—especially if you manage dozens of them.

That’s why we’ve extended Policy Driven PRs to automate third-party Action replacements.

Benefits

  • No more manual search and replace
  • No more repetitive PRs per repository
  • Enforce organization-wide security policies in minutes

How It Works

Here’s how to configure automated Action replacements:

Step 1: Navigate to your StepSecurity dashboard

Picture 1198820695, Picture

Step 2: Click the Orchestrate Security dropdown

Picture 708152870, Picture

Step 3: Click "Policy Driven PRs"

Picture 1519773375, Picture

Step 4: Click "Select Actions" to select all the Actions that you want to be replaced by StepSecurity Maintained Action

Picture 1285191202, Picture

Step 5: In this step, you’ll see a list of third-party Actions currently used in your organization that have a secure, drop-in replacement maintained by StepSecurity.

Picture 1453640382, Picture

Step 6: When the PR is automatically created, you can see that the Action has been replaced by a StepSecurity Action

Picture 1528365560, Picture

Secure Actions at Scale

This enhancement makes it easier than ever to ensure your workflows use secure, audited Actions with minimal effort from your team.

🔒 This feature is currently available only to Enterprise tier users.  

Start your 14-day free trial by installing the StepSecurity app.

🛡️ Already using StepSecurity Enterprise Tier? Log in to your dashboard to begin automating third-party Action replacements today.

🎙️ Join the Webinar

Join us live as we walk through how StepSecurity helps you reduce risk and save time by automating GitHub Actions governance. We’ll demo the new capabilities, share implementation tips, and answer your questions.

👉 Register via the link