Skip to content
View ashishkurmi's full-sized avatar

Organizations

@step-security

Block or report ashishkurmi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Scan for workflow runs that are impacted by trivy action compromise

Go 21 3 Updated Mar 20, 2026

Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages - in seconds.

Go 184 23 Updated Sep 30, 2026

Desktop monitoring and local security reviews for AI agents, with opt-in policy-controlled execution and MCP action tools. Windows primary; macOS/Linux experimental.

JavaScript 154 24 Updated Oct 6, 2026

AI-powered security scanner for Claude Code plugins and skills - LLM analysis, static rules, taint tracking, CI/PR integration, and interactive graph visualization.

Python 15 3 Updated Mar 1, 2026

Reference engine and content library for the Open Vulnerability Remediation Specification (OVRS) — a standard format for describing how to fix vulnerabilities.

Go 43 3 Updated Oct 5, 2026

poutine, a supply chain vulnerability scanner for build pipelines

Go 522 40 Updated Oct 5, 2026

Purpose-built security agent for hosted runners

Go 50 30 Updated Sep 28, 2026

Terraform module for scalable GitHub action runners on AWS

TypeScript 3,141 747 Updated Oct 5, 2026

eBPF-based Security Observability and Runtime Enforcement

C 5,060 618 Updated Oct 6, 2026

AI-Powered Code Reviews for Best Practices & Security Issues Across Languages

Go 23 11 Updated Aug 8, 2025

Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts

JavaScript 50 16 Updated Jul 25, 2026

Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks, de…

Python 210 36 Updated Oct 2, 2026

Build OpenApi specs for your APIs from Burp's traffic using Levo.ai. Also detect the PII in your APIs.

Java 31 4 Updated Oct 2, 2026

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

TypeScript 1,277 117 Updated Oct 6, 2026

Publish from GitHub Actions using multi-factor authentication

TypeScript 300 20 Updated Aug 21, 2026

Orchestrate GitHub Actions Security

Go 332 54 Updated Sep 10, 2026

GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

JavaScript 520 347 Updated Jun 27, 2025