StepSecurity Logo

StepSecurity

1
Commercial
Visit Website

StepSecurity is a platform designed to enhance the security of GitHub Actions CI/CD pipelines. It offers several key features: 1. Harden Runner: Implements network egress control and infrastructure security for GitHub Actions runners, helping prevent supply chain attacks. 2. Risk Discovery: Identifies CI/CD risks and GitHub Actions security misconfigurations. 3. Action Replacement: Substitutes potentially risky third-party Actions with StepSecurity Maintained Actions, reducing the need for forking and maintenance. 4. Orchestration: Automates the implementation of GitHub Actions security best practices through pull requests. 5. Network Egress Filtering: Provides runtime security by blocking egress traffic with an allowlist, compatible with various runner types. 6. Action Risk Assessment: Discovers and evaluates the risk of GitHub Actions used across an organization. 7. Standardization: Helps integrate AppSec tools and security best practices into GitHub Actions workflow files.

FEATURES

ALTERNATIVES

Scan files for viruses and malware with language-agnostic REST API

A DAST solution that performs automated security testing of APIs and web applications within development workflows and CI/CD pipelines.

A series of levels teaching about common mistakes and gotchas when using Amazon Web Services (AWS).

OWASP Damn Vulnerable Web Sockets (DVWS) is a vulnerable web application for client-server communication with numerous vulnerabilities.

Reformat and re-indent bookmarklets, ugly JavaScript, and unpack scripts with options available via UI.

Scanning APK file for URIs, endpoints & secrets.

A Java API for searching and downloading Android applications from Google Play with additional check-in features for generating ANDROID-ID.

A python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.