Robuta

https://docs.stepsecurity.io/github-actions/actions/github-actions-advisor GitHub Actions Advisor | StepSecurity github actions advisorstepsecurity https://docs.stepsecurity.io/github/apps-and-pats Apps & PATs | StepSecurity appspatsstepsecurity https://app.stepsecurity.io/github/ossf/scorecard/actions/runs/2265028928 Run #2265028928 · ossf/scorecard | StepSecurity View detailed insights and events for workflow run #2265028928 in ossf/scorecard runossfscorecardstepsecurity https://docs.stepsecurity.io/start-here/guides Guides | StepSecurity guidesstepsecurity https://trust.stepsecurity.io/ StepSecurity Trust Center Trust Centers are the fastest and most transparent way to demonstrate your company's commitment to security stepsecuritytrustcenter https://krebsonsecurity.com/tag/stepsecurity/ StepSecurity – Krebs on Security stepsecuritykrebs https://docs.stepsecurity.io/dev-machine-guard/system-packages System Packages | Dev Machine Guard | StepSecurity dev machine guardsystem packagesstepsecurity https://docs.stepsecurity.io/github-actions/harden-runner/workflow-runs Workflow Runs | StepSecurity workflowrunsstepsecurity https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross... remote access trojanon npmaxioscompromisedmalicious https://docs.stepsecurity.io/developer-mdm StepSecurity stepsecurity https://docs.stepsecurity.io/github-actions/harden-runner/detections Detections | StepSecurity detectionsstepsecurity