Secure Software Development Scorecard

Track and improve secure software development practices using OpenSSF Scorecard

Identify gaps in AppSec practices using OpenSSF Scorecard
Improve OpenSSF Scorecard scores with auto remediations
Repository governance and CI/CD compliance at scale

Supply Chain Security Simplified

Are you a developer who is tired of fragmented DevOps Security Tools? Are you not making enough progress on security remediations? StepSecurity platform enables DevSecOps security controls and automates remediation in seconds
TRY IT OUT
Main Image

See it in action

electron/electron

sequelize/sequelize

jaegertracing/jaeger

containrrr/watchtower

 flutter/gallery

nginxinc/kubernetes-ingress

cilium / pwru

DataDog/gohai

electron/electron

sequelize/sequelize

jaegertracing/jaeger

containrrr/watchtower

 flutter/gallery

nginxinc/kubernetes-ingress

cilium / pwru

DataDog/gohai

Developers Love StepSecurity

View StepSecurity mentions in developer documentation and blog posts.

More Community Participation Leads to Security Sustainability Progress

StepSecurity focuses on supply chain security, and this is a great addition to the group - OpenJS Foundation

Read more

Apply principle of least privilege to GitHub workflows’ tokens

The killer feature for this app is the ability to automatically create pull-requests to fixes some of the issues identified by scorecards - The Eclipse Foundation

read more

Tales from Fleet security: GitHub configuration and OpenSSF Scorecards

In addition, we pinned actions with hashes to ensure we only run the version we've picked and never a version with extras. StepSecuirty has a great tool to speed the process up!- Fleet

read more

Implementing OSSF Scorecards Across a GitHub Organisation

Thankfully the StepSecurity App was very helpful in identifying minimal token permissions, and finding SHAs for Actions.- Chris Swan

read more

Securing your GitHub org

Fortunately there is a great free online tool that help you by doing all the hard work. The tool was created by StepSecurity. I had the opportunity to talk with the CEO and they listen to the maintainers which is really cool. Thanks to them ❤️ - NodeSecure

read more

Improving your GitHub repositories security setup by adding the OSSF scorecard action

The alert above will give you a link to the StepSecurity Application that can analyze your repository and give you a pull request with the changes to fix the issue - DevOpsJournal

read more

Secure Software Development guide

Check out this nice tool by StepSecurity that can harden the workflow spec - Mattermost

Read more

More Community Participation Leads to Security Sustainability Progress

StepSecurity focuses on supply chain security, and this is a great addition to the group - OpenJS Foundation

read more

Apply principle of least privilege to GitHub workflows’ tokens

The killer feature for this app is the ability to automatically create pull-requests to fixes some of the issues identified by scorecards - The Eclipse Foundation

read more

Secure Software Development guide

Check out this nice tool by StepSecurity that can harden the workflow spec - Mattermost

Read more

Tales from Fleet security: GitHub configuration and OpenSSF Scorecards

In addition, we pinned actions with hashes to ensure we only run the version we've picked and never a version with extras. StepSecuirty has a great tool to speed the process up!- Fleet

read more

Implementing OSSF Scorecards Across a GitHub Organisation

Thankfully the StepSecurity App was very helpful in identifying minimal token permissions, and finding SHAs for Actions.- Chris Swan

read more

Securing your GitHub org

Fortunately there is a great free online tool that help you by doing all the hard work. The tool was created by StepSecurity. I had the opportunity to talk with the CEO and they listen to the maintainers which is really cool. Thanks to them ❤️ - NodeSecure

read more

Improving your GitHub repositories security setup by adding the OSSF scorecard action

The alert above will give you a link to the StepSecurity Application that can analyze your repository and give you a pull request with the changes to fix the issue - DevOpsJournal

read more

Developers Love StepSecurity

Kapiche improves their software supplychain security with StepSecurity.

"Since enabling Harden Runner in ourprojects, we have much higher confidence and observability into what our buildprocess is doing"

-Cam Parry

Staff Site Reliability Engineer

Read our case study

Kapiche improves their software supplychain security with StepSecurity.

"Since enabling Harden Runner in ourprojects, we have much higher confidence and observability into what our buildprocess is doing"

-Cam Parry

Staff Site Reliability Engineer

Read our case study

Kapiche improves their software supplychain security with StepSecurity.

"Since enabling Harden Runner in ourprojects, we have much higher confidence and observability into what our buildprocess is doing"

-Cam Parry

Staff Site Reliability Engineer

Read our case study

Kapiche improves their software supplychain security with StepSecurity.

"Since enabling Harden Runner in ourprojects, we have much higher confidence and observability into what our buildprocess is doing"

-Cam Parry

Staff Site Reliability Engineer

Read our case study

Kapiche improves their software supplychain security with StepSecurity.

"Since enabling Harden Runner in ourprojects, we have much higher confidence and observability into what our buildprocess is doing"

-Cam Parry

Staff Site Reliability Engineer

Read our case study

Kapiche improves their software supplychain security with StepSecurity.

"Since enabling Harden Runner in ourprojects, we have much higher confidence and observability into what our buildprocess is doing"

-Cam Parry

Staff Site Reliability Engineer

Read our case study
View all case studies

Apply principle of least privilege to GitHub workflows’ tokens

We’ve been contacted by StepSecurity in order to evaluate their solution that makes it easy to submit PR with fixes for some issues reported by Scorecard.

Read More

Secure Software Development guide

GitHub Actions are specified in .yml files in the .github/workflows directory inside a GitHub repository.

Read More

Tales from Fleet security: GitHub configuration and OpenSSF Scorecards

We have secured many GitHub Actions/workflows by configuring explicit permissions for jobs. That way, if one of the Actions was compromised, its access to the repository is limited.

Read more

Implementing OSSF Scorecards Across a GitHub Organisation

Thankfully the StepSecurity App was very helpful in identifying minimal token permissions, and finding SHAs for Actions.

Read More

Improving your GitHub repositories security setup by adding the OSSF scorecard action

the alert above will give you a link to the Step Security Application that can analyze your repository and give you a pull request with the changes to fix the issue.

Read More

Testimonials

Remediate Security Issues With One Click

Fix security issues by creating remediation pull requests in seconds.

Remediation pull requests balance the power automation with human oversight of project maintainers

Did you know that 49% developers struggle with security remediations?

Forever free for open-source

Track baseline compliance and close gaps across code repositories at scale

StepSecurity dashboard provides single pane security view for all repositories

Whether you have a large number of private repositories or public ones, StepSecurity can help apply consistent and risk driven baseline policies.

Did you know that on an average, organizations use 45 security tools?

Request an enterprise demo 

Secure Open-Source Repositories with zero friction

Visit SecureRepo, enter repository, and create remediation pull requests.

No app installation or onboarding required for public repositories

Forever free for open-source

Manage private repositories without giving access to StepSecurity 

Outpost deployment lives in customer’s GitHub environment

StepSecurity doesn’t have access to private code repositories. In addition, you can audit all StepSecurity actions via GitHub execution logs. 

Request a demo

Remediate Security Issues With One Click

Fix security issues by creating remediation pull requests in seconds.

Remediation pull requests balance the power automation with human oversight of project maintainers

Did you know that 49% developers struggle with security remediations?

Forever free for open-source

Track baseline compliance and close gaps across code repositories at scale

StepSecurity dashboard provides single pane security view for all repositories

Whether you have a large number of private repositories or public ones, StepSecurity can help apply consistent and risk driven baseline policies.

Did you know that on an average, organizations use 45 security tools?

Request an enterprise demo 

Remediate Security Issues With One Click

Fix security issues by creating remediation pull requests in seconds.

Remediation pull requests balance the power automation with human oversight of project maintainers

Did you know that 49% developers struggle with security remediations?

Forever free for open-source

Manage private repositories without giving access to StepSecurity 

Outpost deployment lives in customer’s GitHub environment

StepSecurity doesn’t have access to private code repositories. In addition, you can audit all StepSecurity actions via GitHub execution logs. 

Request a demo

Testimonials

Wow. @stepsecurity is really making it easy to use best practices for GitHub Actions!

Rob Bos

DevOps Consultant & GitHub Trainer

I have been using the tool to apply security best practices in open source projects and I am quite satisfied. It's a great tool that helps me save a lot of time of deep research and repetitive creation of pull requests. A perfect fit for both avoiding the risks of supply chain attacks and building trust by increasing the OpenSSF Scorecard. Awesome job!

Miguel Nieto

Open Source Advocate

The  @step_security  app saved me a whole lot of time, so thanks for creating it :)  In the first repo I tackled I had 125 issues before running the actions workflows through the app, and a handful to mop up afterwards. That would have been a long hard slog without the app.

Chris Swan

Engineer

Wow. @stepsecurity is really making it easy to use best practices for GitHub Actions!

Rob Bos

DevOps Consultant & GitHub Trainer

I have been using the tool to apply security best practices in open source projects and I am quite satisfied. It's a great tool that helps me save a lot of time of deep research and repetitive creation of pull requests. A perfect fit for both avoiding the risks of supply chain attacks and building trust by increasing the OpenSSF Scorecard. Awesome job!

Miguel Nieto

Open Source Advocate

The  @step_security  app saved me a whole lot of time, so thanks for creating it :)  In the first repo I tackled I had 125 issues before running the actions workflows through the app, and a handful to mop up afterwards. That would have been a long hard slog without the app.

Chris Swan

Engineer

Wow. @stepsecurity is really making it easy to use best practices for GitHub Actions!

Rob Bos

DevOps Consultant & GitHub Trainer

I have been using the tool to apply security best practices in open source projects and I am quite satisfied. It's a great tool that helps me save a lot of time of deep research and repetitive creation of pull requests. A perfect fit for both avoiding the risks of supply chain attacks and building trust by increasing the OpenSSF Scorecard. Awesome job!

Miguel Nieto

Open Source Advocate

The  @step_security  app saved me a whole lot of time, so thanks for creating it :)  In the first repo I tackled I had 125 issues before running the actions workflows through the app, and a handful to mop up afterwards. That would have been a long hard slog without the app.

Chris Swan

Engineer

Track and analyze OpenSSF Scorecard scores at scale

StepSecurity dashboard provides single pane OpenSSF Scorecard scores view for all repositories

Whether you have a large number of private repositories or public ones, StepSecurity can help track and analyze OpenSSF Scorecard scores

Increase Scorecard scores with one click

Fix security issues flagged by OpenSSF Scorecard by remediation pull requests in seconds

Remediation pull requests balance the power automation with human oversight of project maintainers.

Secure Open-Source Repositories with zero friction

Visit SecureRepo, enter repository, and create remediation pull requests.

No app installation or onboarding required for public repositories

Manage private repositories without giving access to StepSecurity

Outpost deployment lives in customer’s GitHub environment

StepSecurity doesn’t have access to private code repositories. In addition, you can audit all StepSecurity actions via GitHub execution logs.

Built on and promote Open-Source

Core platform components are Open-Source for trust and transparency

The platform deploys several open-source security tools such as OpenSSF scorecard.

Did you know that in the Codecov breach, credentials were exfiltrated from thousands of build servers for over 2 months? 

Turbo charge your SOC 2 journey

Deploy mandatory security controls for SOC 2 and ISO with ease

Achieve compliance with SOC 2 controls for your source code repositories and CI/CD pipelines.

Did you know that in the Codecov breach, credentials were exfiltrated from thousands of build servers for over 2 months? 

SecGitOps with StepSecurity Resource Manager 

Create and maintain policy-driven secure GitHub resources 

StepSecurity Resource manager empowers organizations to create repeatable and compliant GitHub resources.

Did you know that in the Codecov breach, credentials were exfiltrated from thousands of build servers for over 2 months? 

GET STARTED

Step up your supply chain security

Free forever plan
No credit card required
Cancel anytime

13,000+ teams host great meetings with Dive

Get more done before, during, and after every meeting.

before meeting

Keep track of notes and progress

Follow up on action items with ease with meeting recaps and notes sent automatically via email and Slack. Now every meeting is well documented and action oriented.