An external GitHub user exploited an exposed npm publishing workflow for @7nohe/openapi-react-query-codegen and shipped ten malicious versions that run attacker code during installation.
A new denied-endpoints input blocks the destinations you name and leaves everything else reachable. Here is why that matters, and how to use it to stop CI from bypassing your package proxy ...
Harden-Runner now secures GitHub Actions jobs running on AWS CodeBuild-hosted runners, on EC2 compute, with managed or custom images.
As software supply chain attacks targeting the NPM ecosystem accelerated throughout 2025, Utility Warehouse’s security team recognized an opportunity to strengthen its posture before an incident ...
This case study is written by Udi-Yehuda Tamar, VP of Platform Engineering and Global CISO at Checkmarx, based on Checkmarx's experience using StepSecurity at scale. The rollout was led by Yevgeny ...
Have a question or feedback? We would love to hear from you. Submit the form below or email us directly at info@stepsecurity.io ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results