惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
B
Blog
博客园_首页
C
Check Point Blog
Microsoft Security Blog
Microsoft Security Blog
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog RSS Feed
M
MIT News - Artificial intelligence
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
量子位
V
V2EX
Y
Y Combinator Blog
Hugging Face - Blog
Hugging Face - Blog
Martin Fowler
Martin Fowler
Recent Announcements
Recent Announcements
I
InfoQ
博客园 - 【当耐特】

Step Security Blog

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity Top 2024 Predictions for CI/CD Security - StepSecurity Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity 10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity 2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity
Uniting Developers and Security: Celebrating the Success ...
2025-07-08 · via Step Security Blog

Introduction

StepSecurity's Orchestration platform serves as a gatekeeper of GitHub repositories, identifying missing security tools and gaps in CI/CD pipeline best practices. By providing developers with a curated list of recommendations, it empowers them to make the choices that fit their projects' needs. They can then leverage the platform to create a pull request, seamlessly integrating the necessary tools and best practices into their repository.

Today, we have hit an important milestone, reaching over 500 open-source projects that have used our platform to improve their security posture. It's a journey worth celebrating, with each step marking our collective progress toward more secure open-source projects.

A Rapid Journey of Growth

On April 6th, we celebrated the adoption of our platform by 300 open-source projects. Just two months later, on June 8th, we were thrilled to announce that the number had risen to 400. In a mere month, that number has increased from 400 to over 500 projects, signifying the increasing trust in and need for effective security practices in the developer community.

StepSecurity Platform in Action

To illustrate how the StepSecurity platform integrates within developers' workflow, we've prepared a video tutorial. The video showcases how developers navigate and use the platform and, most importantly, how it saves them time and reduces complexity.

Your browser does not support the video tag.

Curious to see it for yourself? Feel free to give our platform a try at app.stepsecurity.io/securerepo. Note that you'll need to log in using your GitHub account, but rest assured, our platform doesn't ask for any permissions or personal data. We access public data only to ensure that only past contributors can create a pull request in a project.

Five organizations that have used our platform stand out for their extensive usage: Apache, NodeSecure, Google, Microsoft Azure, and Eclipse. These are our top users in terms of engagement and use, underscoring their high trust in the StepSecurity platform.

You can also browse the pull requests created by the top 50 of the 500 open-source projects that have benefited from our platform at app.stepsecurity.io/securerepo/trending.

The Strength Behind Our Platform

What makes StepSecurity's platform so effective? The answer lies in its ability to integrate various tools and the hardening aspects it offers for the CI/CD pipelines.  

We seamlessly enable the following:

  • StepSecurity Harden-Runner GitHub Action for CI/CD Runtime Security
  • Static Application Security Testing (SAST) tool
  • Software Composition Analysis (SCA) tool
  • OpenSSF Scorecard
  • Dependabot configuration for dependency and CI/CD tool updates  

When it comes to hardening aspects of the CI/CD pipelines, our platform ensures:

  • Setting the least permissions for GitHub action tokens
  • Pinning of GitHub Actions
  • Docker image pinning

To represent this visually, the diagram below provides a high-level view of the integrations and hardening measures undertaken across these 500+ projects.

Conclusion

We are immensely grateful to all the developers and projects that have used our platform and contributed to this milestone.

As of now, StepSecurity's capabilities work for both public and private repositories. Harden-Runner works seamlessly on GitHub-Hosted, Actions Runner Controller (ARC), and self-hosted Virtual Machine (VM) Runners for contextualized insight into network and file events and control over network egress traffic. If you're curious to try it out, you can start with our free trial!

Try StepSecurity for Free