Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

StepSecurity
stepsecurity.io > blog > runtime-security-for-aws-codebuild-hosted-github-actions-runners

Runtime Security for AWS CodeBuild-Hosted GitHub Actions Runners

1+ week, 5+ day ago   (584+ words) That is the environment more and more teams are now pointing their GitHub Actions jobs at. AWS CodeBuild can register itself as a just-in-time GitHub Actions runner, so a job that used to run on ubuntu-latest runs inside your AWS…...

StepSecurity
stepsecurity.io > case-studies > utility-warehouse

How Utility Warehouse Secured Its Software Supply Chain Across CI/CD, NPM, and Developer Machines with StepSecurity

2+ week, 3+ day ago   (316+ words) Utility Warehouse is the UK’s only genuine multiservice utility provider, supplying energy, broadband, mobile, and insurance to over 1.4 million customer accounts. Utility Warehouse, owned by FTSE 250-listed Telecom Plus, is one of the UK’s largest independent energy suppliers. Utility Warehouse’s…...

StepSecurity
stepsecurity.io > blog > arrayref-rust-crate-supply-chain-attack

Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat Execute a Remote Payload at Build Time

3+ week, 2+ day ago   (1076+ words) There is not a single line of malicious code inside arrayref itself, and that is exactly what makes this attack dangerous. The poisoned release changes nothing but its dependency manifest. The malicious crate, meanwhile, ships the genuine proc-macro2 source, so…...