惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

宝玉的分享
宝玉的分享
小众软件
小众软件
J
Java Code Geeks
I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
腾讯CDC
L
LangChain Blog
博客园 - 司徒正美
量子位
Y
Y Combinator Blog
C
Check Point Blog
T
Tailwind CSS Blog
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
N
Netflix TechBlog - Medium
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
B
Blog RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
V
V2EX
阮一峰的网络日志
阮一峰的网络日志

Step Security Blog

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity Top 2024 Predictions for CI/CD Security - StepSecurity Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity 10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity 2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity
Celebrating 1000 Repositories Secured with Harden Runner:...
2026-02-15 · via Step Security Blog

Introduction

We are beyond thrilled to announce a significant milestone for StepSecurity Harden Runner, one of the flagship products of our startup. As of this week, Harden Runner has been successfully adopted by over 1000 public GitHub repositories! This is not just a testament to the value that our security solution brings to the developer community but also a celebration of the collaboration and support we've received since the inception of our product.  

A brief history of Harden Runner

Harden Runner was introduced in February 2022 to prevent SolarWinds and Codecov-style CI/CD supply chain attacks. By installing a security agent on the GitHub-hosted runner, it provides three essential security features:

1. Preventing exfiltration of credentials

2. Detecting tampering of source code during build

3. Detecting compromised dependencies and build tools

After months of rigorous testing, feedback, and improvements, Harden Runner reached General Availability (GA) in November 2022 for GitHub-hosted runners.

The adoption of Harden Runner has seen steady growth since its GA release. It took 10 months for the first 500 repositories to embrace our security solution, but the momentum only accelerated from there. In just five short months, another 500 repositories adopted Harden Runner, bringing our total to a staggering 1000 public GitHub repositories!

This remarkable growth showcases the increasing awareness and importance of security in the software development process. We are grateful for the trust that the developer community has placed in our product, and we're committed to continually enhancing Harden Runner to meet the ever-evolving security challenges in software development.

Harden Runner By The Numbers

In addition to celebrating our milestone of 1000 repositories, we would also like to share some of the impactful statistics that highlight the reach and effectiveness of Harden Runner.

1. CI/ CD pipeline executions: Harden Runner has secured a total of 1,236,972 CI/ CD pipeline executions, a testament to its robust performance and scalability.

2. Public Repositories: Harden Runner is currently being used by 1,012 public repositories. This impressive figure demonstrates the trust and reliance that the open-source community has placed in our product.

3. CI/ CD Pipelines: There are 2,800 GitHub Actions workflows that have integrated Harden Runner in public repositories.  

4. Outbound Network Calls Blocked: Our security solution has successfully blocked over 10,000 outbound network calls to untrusted remote endpoints, protecting numerous repositories from potential exfiltration attempts.

5. Total Releases: We've made 28 releases of Harden Runner since its inception. Each release represents our commitment to continuous improvement, integrating user feedback, and staying ahead of evolving security threats.

These numbers tell a story of commitment, growth, and impact. They reflect not only the effectiveness of Harden Runner but also the trust and collaboration from the developer community. We're excited to see these numbers grow as we continue our mission of securing the software development process.

Spotlight on Top 10 Starred Projects Using Harden Runner

In the spirit of celebrating this milestone, we would also like to shine a spotlight on some of the most popular projects that have adopted Harden Runner. These top 10 repositories, ranked by the number of stars, have not only contributed to our success but are also leading examples of prioritizing security in software development.

Repo name

Stars

Workflow file

Harden Runner insights

nodejs/node

95,409

Link

Link

nvm-sh/nvm

67,058

Link

Link

bazelbuild/bazel

20,806

Link

Link

jaegertracing/jaeger

17,596

Link

Link

Harden Runner: Securing Both Open-Source Communities & Enterprises

We understand the diverse needs of our community and the importance of providing a solution that caters to a wide range of use cases. That's why Harden Runner is designed to work seamlessly with both public and private repositories.

For public open-source repositories, Harden Runner can be easily integrated into your CI/CD workflow without the need to install any App. It provides an additional layer of security, helping you ensure that your open-source projects are safe from tampering and credential exfiltration.

When it comes to private enterprise repositories, Harden Runner GitHub Action, along with the Harden Runner App helps ensure that your proprietary code and credentials are protected during the build process, providing peace of mind and reducing the risk of security breaches. For our paid plans for enterprises, please refer to our website.  

Exciting Future Developments: Harden Runner for Self-Hosted ARC Runners

While we celebrate this milestone, we are equally excited about the road ahead. We are currently developing Harden Runner for self-hosted ARC runners. This move will extend the benefits of our security solution to even more CI/ CD environments. We understand that many organizations and projects have unique requirements that necessitate using self-hosted runners, and we are committed to ensuring that these environments can also benefit from the enhanced security provided by Harden Runner. Please contact us to sign up for a beta for Harden Runner for Self-hosted ARC Runners.  

A Word of Thanks

We would like to express our heartfelt gratitude to all the developers and organizations who have embraced Harden Runner to protect their GitHub-hosted runners. Your invaluable feedback and support have been instrumental in shaping the product into what it is today. We would also like to extend our appreciation to the GitHub community for providing us with an excellent platform to develop and share our solution.

Try StepSecurity for Free