Meta tags:
Headings (most frequently used words):
-
Text of the page (most frequently used words):
stepsecurity (32), and (30), the (30), demo (26), https (22), with (14), supply (13), chain (13), www (13), documentation (12), actions (11), github (9), package (9), machines (9), every (8), security (8), gitbook (8), compromised (8), case (8), studies (8), you (8), harden (7), runner (7), for (7), this (6), com (6), blog (6), npm (6), how (6), ide (5), its (5), all (5), that (5), page (5), goal (5), your (5), detect (4), detected (4), attacks (4), run (4), pipelines (4), docs (4), app (4), hhu8nwchzrrxmxplqevj (4), dev (4), developer (4), files (4), compromise (4), action (4), attack (4), software (4), agents (4), get (4), are (4), block (4), packages (4), extensions (4), across (4), enforce (4), respond (3), threat (3), largest (3), runtime (3), checks (3), automated (3), workflow (3), policies (3), incident (3), coding (3), agent (3), tools (3), see (3), incidents (3), platform (3), need (3), available (3), query (3), question (3), ask (3), here (3), answer (3), runners (3), repos (3), prs (3), network (3), code (3), repositories (3), success (2), capability (2), intelligence (2), which (2), has (2), industry (2), governance (2), started (2), oss (2), cooldown (2), detection (2), search (2), response (2), machine (2), inventory (2), extension (2), local (2), dependency (2), monitoring (2), trusted (2), open (2), source (2), projects (2), enterprises (2), like (2), more (2), changed (2), bitwarden (2), cli (2), hijacked (2), credential (2), stealer (2), targets (2), developers (2), sha1 (2), hulud (2), backstage (2), repository (2), build (2), system (2), xygeni (2), via (2), tag (2), poisoning (2), customer (2), omnissa (2), strengthened (2), mercari (2), hardened (2), chainguard (2), xbow (2), coveo (2), view (2), designed (2), can (2), navigate (2), additional (2), information (2), not (2), current (2), parameter (2), optional (2), start (2), readme (2), specific (2), uses (2), what (2), from (2), use (2), affected (2), outbound (2), ebpf (2), time (2), risky (2), find (2), secure (2), before (2), pull (2), versions (2), llms (2), txt (2), markdown (2), introduction (2), three (2), surfaces (2), lightweight (2), each (2), prevent (2), hint, style, powered, dedicated, team, disclosed, some, endhint, product, area, site, protection, remediation, workspace, getting, gitlab, yfxetun91qnpkgocuqem, azure, devops, dmu7udytqwfdsykteavu, nwcogimqqsclkjx6nz4z, enterprise, wide, dependencies, guard, twdhew5c2aosjzhpi0uc, device, visibility, leading, one, core, solutions, 000, including, giants, microsoft, google, kubernetes, recent, cve, 2025, 30066, advisories, ghsa, mrrh, fwg8, r2c3, axios, download, count, behind, scenes, helped, remediate, bun, staged, cncf, cncfs, alert, popular, data, stealing, malware, backdoored, reverse, shell, backdoor, injected, secures, stories, caught, wild, instructions, published, both, humans, read, reason, over, technical, content, effectively, learn, querying, directly, dynamically, asking, perform, http, request, url, immediate, should, self, contained, written, natural, language, describes, broader, end, ultimately, trying, accomplish, behalf, user, tailor, towards, most, useful, will, contain, direct, relevant, excerpts, sources, mechanism, when, explicitly, present, clarification, context, want, retrieve, related, sections, investigate, level, forensics, lock, down, known, good, endpoints, instantly, exfiltration, attempts, automatically, verify, repo, actually, remediated, map, blast, radius, track, active, center, sweep, during, attacker, planted, tampered, pinpoint, alerted, moment, behaves, abnormally, flag, anomalous, calls, against, learned, baselines, stream, detections, siem, real, any, once, screen, changes, seconds, installed, discover, mcp, servers, replace, third, party, maintained, restrict, egress, roll, out, dependabot, configs, period, new, releases, adopted, safe, manager, configurations, allow, only, approved, malicious, install, registry, complete, index, pages, appending, urls, welcome, hub, implement, powerful, features, manage, operations, efficiently, our, help, effortlessly, maximize, detects, prevents, responds, critical, environments, works, deploying, stage, development, lifecycle, monitor, call, file, write, process, execution, correlating, event, step, triggered, best, practices, through, requests, script, inventories, catch, threats, they, reach, glance, attackers, target, links,
Text of the page (random words):
for the complete documentation index see llms txt https docs stepsecurity io llms txt markdown versions of documentation pages are available by appending md to page urls this page is available as markdown https docs stepsecurity io start here readme md introduction introduction welcome to the stepsecurity documentation hub here you ll find all the information you need to get started with stepsecurity implement its powerful features and manage your security operations efficiently our documentation is designed to help you navigate the platform effortlessly and maximize your use of stepsecurity s tools what is stepsecurity stepsecurity detects prevents and responds to software supply chain attacks across three critical surfaces developer environments code repositories and ci cd pipelines it works by deploying lightweight agents and automated checks at each stage of your development lifecycle on ci cd runners the harden runner agent uses ebpf to monitor every outbound network call file write and process execution correlating each event to the specific workflow step that triggered it on code repositories automated checks block compromised npm packages and enforce security best practices through pull requests on developer machines a lightweight script inventories ai coding agents ide extensions and local packages to catch threats before they reach your pipelines platform at a glance prevent detect and respond across the three surfaces attackers target every capability links to its documentation ️ developer machines code repositories ️ ci cd pipelines ️ prevent block malicious oss packages at install time on dev machines and ci with secure registry demo allow only approved ide extensions demo enforce safe package manager configurations demo block prs that pull in compromised package versions demo enforce a cooldown period before new package releases are adopted demo roll out secure dependabot configs across all repos demo restrict network egress from ci runners with harden runner demo enforce security policies on every workflow run demo replace risky third party actions with stepsecurity maintained actions demo detect discover ai coding agents and mcp servers on every machine demo inventory installed ide extensions demo find a compromised package on dev machines in seconds demo screen every pr for risky dependency changes demo search for any package across repos prs and machines at once demo stream detections to your siem in real time demo detect runtime compromise in ci with ebpf monitoring demo flag anomalous outbound calls against learned network baselines demo get alerted the moment a run behaves abnormally demo respond pinpoint compromised packages and extensions on machines demo detect attacker planted files like tampered ide extension files demo sweep all dev machines during an incident demo track active supply chain attacks in threat center demo map the blast radius which repos prs and machines are affected demo verify every affected repo is actually remediated block exfiltration attempts automatically at runtime demo lock down runners to known good endpoints instantly demo investigate incidents with run level forensics demo hint style success every respond capability is powered by stepsecurity s dedicated threat intelligence team which has detected and disclosed some of the largest supply chain attacks in the industry endhint documentation by product area ci cd security this site harden runner runtime protection github checks automated remediation actions governance and workflow run policies for github actions pipelines github actions https docs stepsecurity io workspace getting started gitlab ci https app gitbook com o hhu8nwchzrrxmxplqevj s yfxetun91qnpkgocuqem azure devops https app gitbook com o hhu8nwchzrrxmxplqevj s dmu7udytqwfdsykteavu oss supply chain security https app gitbook com o hhu8nwchzrrxmxplqevj s nwcogimqqsclkjx6nz4z cooldown policies compromised package detection enterprise wide package search threat intelligence and incident response for package dependencies dev machine guard https app gitbook com o hhu8nwchzrrxmxplqevj s twdhew5c2aosjzhpi0uc device inventory ide extension governance local dependency monitoring and ai coding agent visibility for developer machines trusted by leading open source projects enterprises harden runner one of stepsecurity s core solutions is trusted by 13 000 open source projects and enterprises including industry giants like microsoft google kubernetes and more recent supply chain attacks detected by harden runner tj actions changed files compromise https www stepsecurity io blog harden runner detection tj actions changed files action is compromised cve 2025 30066 https github com advisories ghsa mrrh fwg8 r2c3 axios npm compromise the largest npm supply chain attack by download count https www stepsecurity io blog behind the scenes how stepsecurity detected and helped remediate the largest npm supply chain attack bitwarden cli hijacked on npm credential stealer targets developers github actions and ai tools https www stepsecurity io blog bitwarden cli hijacked on npm bun staged credential stealer targets developers github actions and ai tools sha1 hulud supply chain attack in cncf s backstage repository https www stepsecurity io blog how harden runner detected the sha1 hulud supply chain attack in cncfs backstage repository nx build system compromise https www stepsecurity io blog supply chain security alert popular nx build system package compromised with data stealing malware xygeni action github action backdoored via tag poisoning https www stepsecurity io blog xygeni action compromised c2 reverse shell backdoor injected via tag poisoning customer case studies how omnissa strengthened its software supply chain security with stepsecurity https www stepsecurity io case studies omnissa how mercari hardened its software supply chain with stepsecurity https www stepsecurity io case studies mercari chainguard secures github actions with stepsecurity https www stepsecurity io case studies chainguard how xbow hardened its software supply chain with stepsecurity https www stepsecurity io case studies xbow how coveo strengthened github actions security with stepsecurity https www stepsecurity io case studies coveo see all case studies view customer success stories https www stepsecurity io case studies see every incident stepsecurity has caught in the wild view all incidents https www stepsecurity io incidents agent instructions this documentation is published with gitbook gitbook is the documentation platform designed so that both humans and ai agents can read navigate and reason over technical content effectively learn more at gitbook com querying this documentation if you need additional information that is not directly available in this page you can query the documentation dynamically by asking a question perform an http get request on the current page url with the ask query parameter and the optional goal query parameter get https docs stepsecurity io start here readme md ask goal ask is the immediate question it should be specific self contained and written in natural language goal is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user gitbook uses it to tailor the answer towards what is most useful for that goal the response will contain a direct answer to the question and relevant excerpts and sources from the documentation use this mechanism when the answer is not explicitly present in the current page you need clarification or additional context or you want to retrieve related documentation sections
|