Website profile

Stepsecurity

Close the CI/CD Security Gap. Enhance GitHub Actions Security with StepSecurity Maintained Actions and robust runner runtime security with network egress filtering

  • 23articles · 90d
  • 1+ week agolatest article
  • Jun 16, 2026earliest in window
  • 83%with images
  • 390avg words
articles per day
Categories
  • Software Dev. 21
  • Computers & Electronics 18
  • Science & Technology 17
  • Conflict, War & Peace 5
  • Business & Industrial 2
  • Internet & Telecom 1
  • News 1
  • Software 1
Bylines

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Google News
stepsecurity.io > blog > 7nohe-openapi-react-query-codegen-compromised-npm-publishing-workflow

@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

2+ week, 1+ day ago   (602+ words) The attacker did not need a maintainer npm password or a long lived npm token. The repository accepted an npm publish comment from any pull request participant, checked out that pull request, installed its dependencies, and published packages with a…...

StepSecurity
stepsecurity.io > blog > mass-npm-supply-chain-attack-20-leo-platform-packages-compromised

Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised

2+ mon, 2+ week ago   (377+ words) The following 20 packages are confirmed malicious at the listed versions. All were published simultaneously by an unauthorized actor who gained access to the Leo Platform maintainer credentials. On June 3, 2026 we published a detailed technical analysis of the Miasma campaign, which…...

StepSecurity
stepsecurity.io > blog > prevent-npm-and-python-supply-chain-attacks-on-developer-machines-with-package-configs

Prevent npm and Python Supply Chain Attacks on Developer Machines with Package Configs

2+ mon, 3+ week ago   (588+ words) Two registry-level controls break this cycle: An internal registry or artifact manager, fronted by a Secure Registry, gives you a single controlled path for packages, where cooldown and policy can be enforced and where you have an audit trail instead…...