Categories

Subscribe to Feed

Latest Posts

Showing 0 Items

Harden-Runner Flags Anomalous Outbound Call, Leading to Docker Documentation Update

Harden-Runner detected an unexpected outbound call from Docker across multiple customer environments. Surprisingly, it wasn’t listed in Docker’s allow list, and no EDR tool flagged it. Here’s how we identified it, reported it, and got it added to Docker’s documentation.

StepSecurity Harden-Runner Now Secures GitHub Actions Workflows for Over 5,000 Open Source Projects

We're excited to announce that StepSecurity's Harden-Runner GitHub Action has reached a significant milestone, now securing GitHub Actions workflows for over 5,000 open source projects. This milestone comes at a crucial time when CI/CD security is more important than ever, as evidenced by recent security incidents and our growing impact across the open source ecosystem.

2024 in Review: The Evolution of CI/CD Security & What's Next

How StepSecurity achieved 5X ARR growth while securing over 5,000 open-source repositories in 2024

Prevent Ultralytics Style CI/CD Security Attacks with Network Security Controls

Critical lessons in securing CI/CD pipelines from the Ultralytics GitHub Actions attack

Harden-Runner Detects Anomalous Traffic to api.ipify.org Across Multiple Customers

Starting November 8, 2024, 6:32 PM UTC, StepSecurity Harden-Runner detected unusual outbound network traffic to an unknown domain from multiple GitHub Actions workflow runs across several customers. This systemic incident underscores the importance of real-time monitoring and network visibility for CI/CD runners, showcasing Harden-Runner's effectiveness in identifying and addressing security anomalies.

Migrating From Jenkins to GitHub Actions: A Step-by-Step Guide

Learn the step-by-step process for migrating from Jenkins to GitHub Actions. This guide covers key differences, best practices, and solutions to common challenges, helping DevOps teams streamline CI/CD workflows efficiently.

There are no blog posts matching your criteria at this time.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.