Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. StepSecurity/
  3. StepSecurity CI/CD Security

StepSecurity CI/CD Security

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 40/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 1 known CVE (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

CI/CD security platform for GitHub Actions with runtime threat detection

by StepSecurity · stepsecurity.io · source ↗

Known CVEs (1)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2024-52587 ↗HIGH 8.82024

    StepSecurity's Harden-Runner provides network egress filtering and runtime security for GitHub-hosted and self-hosted runners. Versions of step-security/harden-runner prior to v2.10.2 contain multiple…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Software Supply Chain Security products

see all →
  • Apiiro Deliver · Apiiro
  • Apiiro SSCS · Apiiro
  • Aqua Software Supply Chain Security · Aqua Security
  • BoostSecurity Cloud-speed Compliance · BoostSecurity
  • BoostSecurity Software Supply Chain Protection · BoostSecurity
  • CI/CD Security · Cycode
  • Chainguard Containers · Chainguard
  • Chainguard Libraries · Chainguard