Categories

Subscribe to Feed

Latest Posts

Showing 0 Items

Securing GitHub Copilot in GitHub Actions with Harden-Runner

AI coding agents like GitHub Copilot are powerful—but they can be a black box in CI/CD. Copilot’s firewall blocks unauthorized network calls, but it doesn’t show what processes run, which APIs are hit, or what packages get installed. StepSecurity Harden-Runner closes that gap with runtime visibility into every action Copilot takes—delivering true defense-in-depth for secure AI-driven development

When AI Meets CI/CD: Coding Agents in GitHub Actions Pose Hidden Security Risks

As organizations integrate AI coding agents into their development pipelines, new security considerations emerge. While these tools accelerate development, they require thoughtful security approaches to protect against novel attack vectors like Rules File Backdoor attacks and GITHUB_TOKEN compromise.

Supply Chain Security Alert: eslint-config-prettier Package Shows Signs of Compromise

We are currently investigating a potential supply chain security incident involving the eslint-config-prettier npm package. This widely-used package, which helps developers maintain consistent code formatting by turning off ESLint rules that conflict with Prettier, appears to have had multiple versions published with suspicious modifications.

Calculate Your CI/CD Security ROI with StepSecurity's New ROI Calculator

We're excited to announce the launch of our new ROI Calculator—a powerful tool that helps organizations assess their current CI/CD security posture and calculate the tangible time-savings and risk-avoidance benefits of implementing StepSecurity's CI/CD Security platform.

7,000 Open-Source Projects Now Secured by Harden-Runner

StepSecurity’s Harden-Runner now protects over 7,000 GitHub repositories with real-time CI/CD runtime monitoring, threat detection, and supply chain security enforcement—backed by features like impostor commit alerts, process-based detections, and GitLab support.

The GitHub Warning Everyone Ignores: 'This Commit Does Not Belong to Any Branch'

Several popular GitHub Actions have release processes where the release commit does not belong to any branch on the action repository.

Replace Third-Party Actions with StepSecurity Maintained Actions via Automated Pull Requests

Policy Driven PRs now upgrade third-party Actions to StepSecurity Maintained versions across your entire organization

StepSecurity Is Now Available on AWS Marketplace

The StepSecurity App is now available on AWS Marketplace—simplifying procurement, deployment, and CI/CD security in one place

There are no blog posts matching your criteria at this time.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.