Categories

Latest Posts

Showing 0 Items

Prevent Ultralytics Style CI/CD Security Attacks with Network Security Controls

Critical lessons in securing CI/CD pipelines from the Ultralytics GitHub Actions attack

PyTorch Supply Chain Compromise

The vulnerability in PyTorch’s CI/CD pipeline highlights the critical need for securing self-hosted runners

Harden-Runner Detects Anomalous Traffic to api.ipify.org Across Multiple Customers

Starting November 8, 2024, 6:32 PM UTC, StepSecurity Harden-Runner detected unusual outbound network traffic to an unknown domain from multiple GitHub Actions workflow runs across several customers. This systemic incident underscores the importance of real-time monitoring and network visibility for CI/CD runners, showcasing Harden-Runner's effectiveness in identifying and addressing security anomalies.

Migrating From Jenkins to GitHub Actions: A Step-by-Step Guide

Learn the step-by-step process for migrating from Jenkins to GitHub Actions. This guide covers key differences, best practices, and solutions to common challenges, helping DevOps teams streamline CI/CD workflows efficiently.

StepSecurity Harden-Runner Featured in the GitHub Action in Action Book

GitHub Actions in Action highlights Harden-Runner as a solution for monitoring and limiting network access from GitHub runners.

Implementing an Internal GitHub Actions Marketplace with StepSecurity

Third-party GitHub Actions accelerate CI/CD pipeline development but pose significant supply chain risks for enterprises. Implementing an internal GitHub Actions marketplace with StepSecurity allows organizations to securely vet, approve, and maintain these Actions, balancing developer productivity with robust security standards.

Milestone Achieved: 2500+ Public Repositories Secured with Harden-Runner

We're celebrating 2500+ public repositories secured with Harden-Runner! Read this blog to explore how there is a rising need for CI/CD infrastructure security, the impact of Harden-Runner, its new features and how it has become a part of developers' vocabulary.

There are no blog posts matching your criteria at this time.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.