惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
Recent Announcements
Recent Announcements
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog
罗磊的独立博客
月光博客
月光博客
J
Java Code Geeks
A
About on SuperTechFans
Microsoft Security Blog
Microsoft Security Blog
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
F
Fortinet All Blogs
U
Unit 42
C
Check Point Blog
Martin Fowler
Martin Fowler
有赞技术团队
有赞技术团队
博客园 - 叶小钗
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
酷 壳 – CoolShell
酷 壳 – CoolShell
Blog — PlanetScale
Blog — PlanetScale
大猫的无限游戏
大猫的无限游戏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志
MyScale Blog
MyScale Blog

Step Security Blog

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity Top 2024 Predictions for CI/CD Security - StepSecurity Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity 10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity 2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity
StepSecurity Is Sponsoring GitHub Universe 2025 - StepSec...
2025-10-08 · via Step Security Blog

GitHub Universe is where the global developer community comes together to learn, share, and explore the future of software development. From product announcements to hands-on workshops, it’s the stage where innovation in DevOps, AI, and open source takes center stage.

At StepSecurity, our mission is to make GitHub Actions workflows secure by default. That’s why we’re thrilled to announce that we are a Bronze Sponsor of GitHub Universe 2025.

📅 When: October 28–29, 2025

📍 Where: Fort Mason Center, San Francisco, Booth #102

Why GitHub Universe Matters

CI/CD pipelines are the backbone of modern software delivery — but they’re also an increasingly common target for supply chain attacks. With GitHub Actions at the heart of countless development workflows, securing these pipelines isn't optional anymore — it's critical.

GitHub Universe is the perfect venue for us to highlight solutions that protect developers from workflow misconfigurations, compromised actions, and secrets exfiltration risks. By sponsoring this event, we’re investing directly in the developer community that depends on GitHub Actions every day.

Experience StepSecurity in Action

Stop by Booth #102 to see how we're revolutionizing GitHub Actions security:

  • Real-world threat detection: Watch how StepSecurity Harden-Runner caught the tj-actions/changed-files incident in real-time through baseline monitoring of outbound network calls
  • Third-party actions governance: Evaluate risks from 3rd party actions and discover our secure, drop-in replacements for risky actions
  • Policy enforcement: See automated workflow blocking in action when security standards aren't met

What You'll Take Away

  • Best practices for hardening GitHub Actions workflows against emerging threats
  • Hands-on guidance for implementing security guardrails in your pipelines
  • Awesome swag to remember us by! 🎁

Connect with our team to discuss how we can help you implement guardrails and block risky automation in your pipelines.

Can't Make It? We've Got You Covered

Enter our raffle for FREE and discounted passes! We're giving away tickets to GitHub Universe 2025. Simply fill out this form before October 13th for your chance to join us.

Join the Movement

We’re proud to stand alongside GitHub and the developer community at Universe 2025. Whether you’re attending in person or online, we invite you to join us in shaping a more secure future for CI/CD.

See you at GitHub Universe!