惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
V
V2EX
小众软件
小众软件
WordPress大学
WordPress大学
Apple Machine Learning Research
Apple Machine Learning Research
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
MongoDB | Blog
MongoDB | Blog
C
Check Point Blog
S
Schneier on Security
C
Cybersecurity and Infrastructure Security Agency CISA
The Cloudflare Blog
V
Vulnerabilities – Threatpost
The Hacker News
The Hacker News
T
Threatpost
T
Tenable Blog
aimingoo的专栏
aimingoo的专栏
IT之家
IT之家
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
C
CERT Recently Published Vulnerability Notes
U
Unit 42
Spread Privacy
Spread Privacy
博客园 - 司徒正美
Hacker News: Ask HN
Hacker News: Ask HN
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
阮一峰的网络日志
阮一峰的网络日志
SecWiki News
SecWiki News
云风的 BLOG
云风的 BLOG
The Register - Security
The Register - Security
AWS News Blog
AWS News Blog
月光博客
月光博客
Security Latest
Security Latest
H
Heimdal Security Blog
S
Secure Thoughts
博客园 - 聂微东
PCI Perspectives
PCI Perspectives
博客园 - 叶小钗
Scott Helme
Scott Helme
O
OpenAI News
Google DeepMind News
Google DeepMind News
Google DeepMind News
Google DeepMind News
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Security @ Cisco Blogs
NISL@THU
NISL@THU
S
Securelist
Latest news
Latest news
P
Proofpoint News Feed
博客园 - 【当耐特】

Step Security Blog

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity Top 2024 Predictions for CI/CD Security - StepSecurity Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity 10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity 2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity How to Use Docker in Actions Runner Controller (ARC) Runners Securely - StepSecurity Celebrating 1000 Repositories Secured with Harden Runner: A Journey of Growth and Collaboration - StepSecurity StepSecurity Detects Early Supply Chain Risk Signals in kilocode npm - StepSecurity Another npm Supply Chain Attack: The 'is' Package Compromise - StepSecurity anthropics/claude-code-action Security: How to Secure Claude Code in GitHub Actions with Harden-Runner - StepSecurity Harden-Runner detection: tj-actions/changed-files action is compromised - StepSecurity StepSecurity's Catalog of Fixes - StepSecurity Orchestrating Security: StepSecurity's Impact on 400+ Repositories and Future Plans - StepSecurity Announcing Anomalous Outbound Call Detection Using Machine Learning - StepSecurity Announcing GitHub Actions Advisor and StepSecurity Maintained Actions - StepSecurity Analysis of Backdoored XZ Utils Build Process with Harden-Runner - StepSecurity Announcing General Availability of Harden Runner - StepSecurity Milestone Achieved: 2500+ Public Repositories Secured with Harden-Runner - StepSecurity Build secretless CI/CD pipelines using wait-for-secrets - StepSecurity Introducing Apps & PATs: Centralized Visibility for GitHub Apps and Personal Access Tokens - StepSecurity CVE-2026-22709: Critical Sandbox Escape Vulnerability in vm2 - StepSecurity StepSecurity Now Supports Dark Mode - StepSecurity 2025 in Review: The Evolution of Supply Chain Security & What's Next - StepSecurity Bake Harden-Runner Into GitHub's Custom Runner Images for Organization-Wide CI/CD Security - StepSecurity StepSecurity Is Now Available on Azure Marketplace - StepSecurity Critical Remote Code Execution Vulnerabilities Discovered in React Server Components and Next.js - StepSecurity How Harden Runner Detected the Sha1-Hulud Supply Chain Attack in CNCF's Backstage Repository - StepSecurity Sha1-Hulud: The Second Coming - Zapier, ENS Domains, and Other Prominent NPM Packages Compromised - StepSecurity Supply Chain Security Alert: eslint-config-prettier Package Shows Signs of Compromise - StepSecurity 9,000 Open-Source Projects Now Secured by Harden-Runner - StepSecurity Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages - StepSecurity Introducing npm Package Search: Find Where Any Package Was Introduced Across Your GitHub Organizations - StepSecurity StepSecurity Is Sponsoring GitHub Universe 2025 - StepSecurity s1ngularity: Popular Nx Build System Package Compromised with Data-Stealing Malware - StepSecurity Introducing StepSecurity Threat Intelligence: Real-Time Supply Chain Attack Alerts for Your SIEM - StepSecurity 8,000 Strong: Harden-Runner's Growing Impact on CI/CD Security - StepSecurity Securing Google Gemini in GitHub Actions with Harden-Runner - StepSecurity GhostAction Campaign: Over 3,000 Secrets Stolen Through Malicious GitHub Workflows - StepSecurity Securing GitHub Copilot in GitHub Actions with Harden-Runner - StepSecurity Calculate Your CI/CD Security ROI with StepSecurity's New ROI Calculator - StepSecurity How StepSecurity Harden Runner Detected Unexpected Microsoft Defender Installation on GitHub-hosted Ubuntu Runners - StepSecurity StepSecurity Harden Runner: Detect source code tampering during the build process - StepSecurity Suspicious Tag Movement in AWS’s GitHub Action: What Happened and Why It Matters - StepSecurity When 'Changed Files' Changed Everything: Our Black Hat 2025 Presentation on the tj-actions Supply Chain Breach - StepSecurity Lessons from AWS CodeBuild’s Memory-Dump Incident (CVE-2025-8217) - StepSecurity Supply Chain Security Alert: num2words PyPI Package Shows Signs of Compromise - StepSecurity When AI Meets CI/CD: Coding Agents in GitHub Actions Pose Hidden Security Risks - StepSecurity The GitHub Warning Everyone Ignores: 'This Commit Does Not Belong to Any Branch' - StepSecurity 8 GitHub Actions Secrets Management Best Practices to Follow - StepSecurity reviewdog GitHub Actions are compromised - StepSecurity 7,000 Open-Source Projects Now Secured by Harden-Runner - StepSecurity Replace Third-Party Actions with StepSecurity Maintained Actions via Automated Pull Requests - StepSecurity StepSecurity Is Now Available on AWS Marketplace - StepSecurity Introducing StepSecurity Artifact Monitor: Detect Unauthorized Software Releases in minutes, not months - StepSecurity Introducing Workflow Run Policies: Guardrails for Blocking Non-Compliant GitHub Actions Runs - StepSecurity Harden-Runner Detects New Traffic to release-assets.githubusercontent.com Across Multiple Customers - StepSecurity Grafana GitHub Actions Security Incident - StepSecurity Export Harden-Runner Security Insights and Detections to Amazon S3 - StepSecurity Evolving Harden-Runner’s disable-sudo Policy for Improved Runner Security - StepSecurity Announcing Policy-Driven Automated Pull Requests for CI/CD Misconfiguration Remediation - StepSecurity Announcing StepSecurity’s Integration with RunsOn: Secure and Optimized CI/CD Pipelines - StepSecurity Secure Repo Just Got Better: New Features for GitHub Actions Security Best Practices - StepSecurity Why Compliance Auditors Are Looking at Your CI/CD Runners - And How to Prepare - StepSecurity Harden-Runner Flags Anomalous Outbound Call, Leading to Docker Documentation Update - StepSecurity StepSecurity Harden-Runner Now Secures GitHub Actions Workflows for Over 5,000 Open Source Projects - StepSecurity GitHub Actions Pwn Request Vulnerability - StepSecurity Prevent Ultralytics Style CI/CD Security Attacks with Network Security Controls - StepSecurity PyTorch Supply Chain Compromise - StepSecurity Unified Network Egress View: Centralize GitHub Actions Network Destinations for Your Enterprise - StepSecurity Uniting Developers and Security: Celebrating the Success of 500+ Open Source Projects Using StepSecurity's Orchestration Platform - StepSecurity 5 Effective Third-Party GitHub Actions Governance Best Practices - StepSecurity StepSecurity Recognized Among CRN’s "10 Hottest DevOps Startups Of 2024" - StepSecurity Streamline Your GitHub Actions Workflows with StepSecurity’s Latest Feature - StepSecurity StepSecurity Steps Up the Security Game with SOC 2 Type 2 Compliance - StepSecurity StepSecurity's Alignment with CISA's CI/CD Security Guidance - StepSecurity
Introducing the NPM Package Cooldown Check - StepSecurity
2025-09-08 · via Step Security Blog

Supply chain attacks on open-source packages are a growing concern for platform and security teams. Today, we’re excited to announce the NPM Package Cooldown Check, a new GitHub pull request (PR) check designed to automatically block PRs that introduce new npm package versions. In simple terms, if a PR tries to use an npm package release that came out within the last two days (or within a configurable “cooldown” period), this check will fail the PR. This gives your team a short waiting window before adopting brand-new dependencies, providing a crucial safety net against malicious releases. It’s an accessible, developer-friendly guardrail that integrates directly into your GitHub workflow, helping protect your applications from supply chain attacks without slowing down development.

This feature is part of our broader initiative to bake security into the development lifecycle. Alongside the Cooldown Check, we’re rolling out additional GitHub checks to catch other supply chain threats – from dangerous GitHub Actions workflow vulnerabilities (like “PWN Request” flaws) to script injection issues in CI pipelines. In this post, we’ll explain how the NPM Package Cooldown Check works, walk through an example, discuss the rationale behind it, and provide guidance on adopting it in your environment.

The NPM Package Cooldown Check is a lightweight automated verification step that runs on each pull request. Its job is straightforward: detect any npm dependency introduced or updated in the PR that was published within the last 2 days (48 hours) and fail the PR if such a dependency is found.  

The “cooldown” period is configurable – by default it’s set to 2 days, but your organization can adjust it to a longer or shorter window based on your risk tolerance. Once the cooldown period has passed for that package version, the check will automatically clear with no manual intervention needed. In practice, this means if you open a PR that updates a library to a version released yesterday, the PR will be blocked; but if you simply wait until that version is 2+ days old, the check will pass and you can merge as normal.

How the NPM Package Cooldown Check Works
Why Enforce a Cooldown Period?  

You might wonder: why delay updates at all? The rationale is rooted in hard lessons from recent software supply chain attacks. Most malicious package releases are discovered within the first 24 hours of being published, often by automated scanners, security researchers, or the package maintainers themselves. The projects that get compromised are typically those that rush to adopt the new version immediately. By introducing a short waiting period before allowing new dependencies, teams can dramatically reduce their exposure to fresh attacks while still keeping their dependencies up to date.

The NX compromise in npm is a stark example of why early adoption of every new release can be risky. Attackers managed to slip a malicious version into the registry, and within hours, developers who immediately pulled the update were at risk of running compromised code. Fortunately, the issue was detected and the package flagged within the first 24 hours. The same pattern has played out with other packages, like es-lint and is, where the compromises were caught quickly but not before exposing early upgraders.

This is exactly the problem that the Cooldown Check addresses. By automatically enforcing a short waiting period before new releases can be adopted, it gives the ecosystem time to react and flag issues. Instead of relying only on vulnerability scanners or CVE announcements after the fact, the Cooldown Check proactively pauses on unvetted code.

The safeguard is especially valuable for teams using automated dependency update tools like Dependabot. With the Cooldown Check enabled, even Dependabot PRs will be flagged if they point to a just-released package, reducing the risk of accidentally merging a compromise. A 48-hour delay is a small trade-off for a significant reduction in exposure.

In the screenshot above, version 20.12.0 was compromised while 20.10.0 was not. However, since Dependabot automatically updated the dependency, the repository ended up using the compromised version. This pattern is something we’ve observed across several npm supply chain attacks: automated dependency upgrade tools like Dependabot and RenovateBot will quickly create pull requests to bump from a safe version to the compromised one shortly after release. Because many developers trust these tools and merge the PRs without much scrutiny, the malicious code often spreads rapidly before the compromise is flagged.

Walkthrough: Blocking a Newly Released Package in a PR

The screenshot below shows how the NPM Package Cooldown Check surfaces a failure on a pull request. In this example, a developer attempted to bump a dependency to a version published just hours earlier. The Cooldown Check ran as part of the PR’s checks and flagged the new version as too recent. In the PR’s status panel, you can see a failed check with details listing the offending package name, the version change (from the previous version to the new one), the file (e.g. package.json or lockfile) where the change occurred, and the new version’s release date/time. The check message even notes when it will pass automatically indicating the exact time the 2-day cooldown will be satisfied. This immediate feedback allows the team to hold off merging the PR until the flagged dependency has aged past the safe threshold, at which point the check will turn green on its own.

NPM Package Cooldown Check failed because the published package version is less than 2 days old

To summarize the developer experience with this check:

  1. A developer (or bot) opens a PR that adds or updates one or more npm package versions.
  1. The NPM Package Cooldown Check runs during the PR’s CI workflow.
  1. If any introduced package version was released within the last X days (e.g. 2 days), the check fails and the PR is blocked from merging.
  1. The PR displays a clear error with information about which package is too new and how long to wait.
  1. Once the cooldown period elapses, the check automatically re-runs and passes (assuming no other issues), unblocking the PR. The team can then merge the PR knowing the dependency had a little time to “soak” in the community.

Follow this interactive demo to see how it works:

Adopting the Cooldown Check in Your Pipeline

Getting started with the NPM Package Cooldown Check is straightforward. The check can be enabled as part of your GitHub PR workflow using our platform. Platform/ Security engineers can roll it out organization-wide or to specific repositories as a status check on pull requests. To enable this follow the information in our docs

Importantly, the Cooldown Check is not meant to block critical security patches. If an urgent fix is released upstream, developers can still merge it right away. In these cases, the check will initially fail because the new package hasn’t cleared the cooldown period, but a StepSecurity org admin can override the result and approve the PR. This ensures teams maintain agility for emergency updates while still benefiting from a protective default posture against compromised packages.

Part of a Broader Security Initiative

The NPM Package Cooldown Check is one piece of a larger effort to strengthen software supply chain security via GitHub-native checks. As mentioned earlier, we are extending our platform with additional automated PR and CI/CD checks to tackle other classes of vulnerabilities that have been plaguing modern pipelines.

NPM Package Compromised Updates Check

This control ensures that no pull request introduces or updates a dependency that is known to be compromised. StepSecurity continuously monitors the npm ecosystem for emerging threats and maintains an internal database of compromised packages, updated in real time. In many cases, this database is updated before an official CVE is published, meaning developers can block the use of a malicious package faster than traditional vulnerability scanners allow. If a pull request uses a compromised package, the check fails and prevents the merge, eliminating a major attack vector and helping teams respond to incidents at the speed of the ecosystem.

PWN Request Check

This control inspects GitHub Actions workflows for patterns that may allow a PWN Request vulnerability. It detects insecure configurations such as workflows triggered by pull_request_target that can be exploited by malicious forked PRs, and it flags these risks before they can be used to execute unauthorized code in your CI environment.

PWN Request Vulnerability Check failed becuase the workflow is vulnerable to pwn requests

Script Injection Check

This control scans GitHub Actions workflows for script injection vulnerabilities. It identifies workflows that use overly permissive triggers or unsanitized external inputs and surfaces warnings or blocking checks so issues can be resolved before attackers exploit them

Script Injection Vulnerability Check failed because the workfow is vulnerable to Script injection

Conclusion and Next Steps

The introduction of the NPM Package Cooldown Check marks an important step toward making supply chain security frictionless and proactive. We believe that security tools work best when they operate in the background of the developer workflow – providing timely alerts and guardrails without overwhelming developers. With this new check, teams can continue to update dependencies confidently, knowing that an extra set of eyes (and a little timer) are watching out for them.

Get started with this feature by starting your free trial