@step-security bot account for creating PRs. Fix CI/CD software supply chain security issues using https://app.stepsecurity.io/securerepo
-
StepSecurity
- https://app.stepsecurity.io/securerepo
- @step_security
Block or Report
Block or report step-security-bot
Report abuse
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned
-
step-security/harden-runner Public
Unlock Unprecedented Security for Your GitHub-Hosted CI/CD Pipeline with the Harden-Runner Agent - Protect Against SolarWinds and Codecov-Type Attacks
-
Secure GitHub Actions CI/CD workflows via automated remediations
2,575 contributions in the last year
Less
More
Contribution activity
February 2023
Created 8 commits in 2 repositories
Created 3 repositories
Opened 28 pull requests in 8 repositories
step-security/secure-workflows
10
open
1
merged
- [KB] Add GitHub token permissions for frouioui/paths-filter
- [KB] Add GitHub token permissions for mheap/github-action-required-labels
- [KB] Add GitHub token permissions for svenstaro/upload-release-action
- [KB] Add GitHub token permissions for Sibz/github-status-action
- [KB] Add GitHub token permissions for Sibz/github-status-action
- [KB] Add GitHub token permissions for crazy-max/ghaction-github-pages
- [KB] Add GitHub token permissions for trunk-io/trunk-action
- [KB] Add GitHub token permissions for sonarsource/sonarqube-scan-action
- [KB] Add GitHub token permissions for actions-ecosystem/action-regex-match
- [KB] Add GitHub token permissions for pat-s/always-upload-cache
- [KB] Add GitHub token permissions for actions/add-to-project
material-foundation/flutter-packages
5
merged
2
closed
- [StepSecurity] ci: Pin Actions to a full length commit SHA
- [StepSecurity] Apply security best practices
- [StepSecurity] ci: Pin Actions to a full length commit SHA
- [StepSecurity] ci: Pin Actions to a full length commit SHA
- [StepSecurity] Restrict permissions for GITHUB_TOKEN
- [StepSecurity] ci: Restrict permissions for GITHUB_TOKEN
- [StepSecurity] ci: Pin Actions to a full length commit SHA