Company intelligence
StepSecurity
Prevent, Detect, and Respond to Software Supply Chain Attacks
About StepSecurity
StepSecurity secures the software supply chain end to end, across developer machines, code repos, and CI/CD pipelines. We help teams prevent, detect, and respond to supply chain attacks at every stage of software delivery, from the first line of code a developer writes to the final build that ships. On developer machines, StepSecurity monitors AI coding agents, IDE extensions, and packages, and detects compromised dependencies before they spread. In code repos, it raises automated security pull requests, enforces branch protection, and flags compromised dependencies on every pull request. In CI/CD pipelines, StepSecurity Harden-Runner enforces runner-level network egress controls, detects anomalies in every workflow step, and provides secure drop-in replacements for third-party actions. StepSecurity is powered by a dedicated threat intelligence team that has detected and disclosed some of the largest supply chain attacks in the industry, including the tj-actions/changed-files compromise, the axios npm attack, and the Trivy compromise. Over 15,000 open-source projects, including those from the Cybersecurity and Infrastructure Security Agency (CISA), Google, Microsoft, Datadog, Kubernetes, Node.js, and Ruby, use StepSecurity. Our enterprise tier is deployed at customers in the crypto, healthcare, and cybersecurity industries. The StepSecurity platform secures more than 35,000,000 CI/CD job runs every week.
Verified activity
Signals from StepSecurity
10 published signals
Partnerships
StepSecurity welcomed Checkmarx as a customer in May.
Reported by StepSecurity
Research & Knowledge
StepSecurity published a case study written by Udi-Yehuda Tamar, VP of Platform Engineering and Global CISO at Checkmarx.
Reported by StepSecurity
Products & Services
StepSecurity released Dev Machine Guard to inventory every browser extension installed across a developer fleet, what each one is currently permitted to do, where it came from, and which devices are running it.
Reported by StepSecurity
Research & Knowledge
StepSecurity published a case study written by Udi-Yehuda Tamar, VP of Platform Engineering and Global CISO at Checkmarx.
Reported by Varun Sharma
Partnerships
StepSecurity welcomed Checkmarx as a customer in May.
Reported by Varun Sharma
Technology & Infrastructure
StepSecurity provided comprehensive visibility into outbound calls from GitHub Actions runners.
Reported by StepSecurity
Technology & Infrastructure
StepSecurity detected and blocked a PR that compromised a downstream NPM package introduced by a new dependency.
Reported by StepSecurity
Customers & Market
StepSecurity customer Utility Warehouse is the UK's only genuine multiservice utility provider supplying energy, broadband, mobile, and insurance to over 1.4 million customer accounts.
Reported by StepSecurity
Technology & Infrastructure
StepSecurity Harden Runner’s baseline anomaly detection was highlighted as the capability that stood out most.
Reported by StepSecurity
Products & Services
StepSecurity published research on an open-source worm named ChainDrop, which was cited in a write-up by Jared Wray.
Reported by Ashish Kurmi