-
🔭 I’m currently working on my startup StepSecurity, to thwart software supply chain attacks
I was a Principal Security Software Engineering Manager at Microsoft, and used to lead the Green Team, to solve high-risk systemic security issues in Azure.
In 2006, I had won an All-India contest organized by Microsoft called the Security Shootout Contest, in which 11,200 developers participated, and for which an SUV was the first prize!
-
📫 How to reach me: https://www.linkedin.com/in/varunsharma07/
CEO/Co-Founder @step-security
-
StepSecurity
- Seattle, WA
- https://www.stepsecurity.io
- @varunsh_coder
Highlights
Pinned Loading
-
step-security/harden-runner
step-security/harden-runner PublicHarden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…
-
step-security/secure-repo
step-security/secure-repo PublicOrchestrate GitHub Actions Security
868 contributions in the last year
Day of Week | March Mar | April Apr | May May | June Jun | July Jul | August Aug | September Sep | October Oct | November Nov | December Dec | January Jan | February Feb | March Mar | ||||||||||||||||||||||||||||||||||||||||
Sunday Sun | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Monday Mon | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Tuesday Tue | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Wednesday Wed | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Thursday Thu | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Friday Fri | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Saturday Sat |
Less
No contributions.
Low contributions.
Medium-low contributions.
Medium-high contributions.
High contributions.
More
Contribution activity
March 2025
Created 9 commits in 1 repository
Created a pull request in step-security/harden-runner that received 3 comments
Opened 5 other pull requests in 3 repositories
step-security/harden-runner
2
merged
-
Address vulnerabilities
This contribution was made on Mar 21
-
Update readme
This contribution was made on Mar 8
step-security/github-actions-goat
2
closed
-
Update publish.yml
This contribution was made on Mar 3
-
Create Harden-Runner-Showcase.yml
This contribution was made on Mar 2
github/advisory-database
1
merged
-
[GHSA-mrrh-fwg8-r2c3] tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.
This contribution was made on Mar 16
Reviewed 21 pull requests in 13 repositories
step-security/changed-files
6 pull requests
-
[StepSecurity] ci: Harden GitHub Actions
This contribution was made on Mar 20
-
removing subscription check to make the Action available to everyone
This contribution was made on Mar 15
-
action release
This contribution was made on Mar 15
-
audit package workflow added
This contribution was made on Mar 15
-
change-files forking done and tested
This contribution was made on Mar 15
-
initial changes
This contribution was made on Mar 15
step-security/test-reporter
2 pull requests
-
test vulnerabilities fixed through osv-scanner
This contribution was made on Mar 24
-
Release
This contribution was made on Mar 24
step-security/github-action-get-latest-release
2 pull requests
-
installed ncc as a dev dep to run build in workflow
This contribution was made on Mar 24
-
forked repo from upstream
This contribution was made on Mar 24
step-security/harden-runner
2 pull requests
-
Update actions/upload-artifact in Scorecards from v3.0.0 to v4.6.1
This contribution was made on Mar 4
-
[StepSecurity] ci: Harden GitHub Actions
This contribution was made on Mar 3
step-security/runs-on-cache
1 pull request
-
forked from release
This contribution was made on Mar 25
step-security/multi-labeler
1 pull request
-
fix: forked from upstream
This contribution was made on Mar 25
step-security/assign-author
1 pull request
-
feat: vulnerabilities fixed manually thorugh osv scanner
This contribution was made on Mar 21
step-security/envsubst-action
1 pull request
-
forked from upstream repo
This contribution was made on Mar 20
step-security/github-actions-slack
1 pull request
-
forked from upstream repo
This contribution was made on Mar 20
step-security/action-gh-release
1 pull request
-
forked upstream repo and code built
This contribution was made on Mar 19
step-security/reviewdog-action-setup
1 pull request
-
forked upstream repo
This contribution was made on Mar 18
step-security/rust-cache
1 pull request
-
chore: Cherry-picked changes from upstream
This contribution was made on Mar 13
step-security/action-semantic-pull-request
1 pull request
-
fix: included mit license terms
This contribution was made on Mar 11
Created an issue in tj-actions/changed-files that received 56 comments
Multiple tags in this action are compromised
Example this tag was just updated 3 hours back and is potentially exfiltrating credentials https://github.com/tj-actions/changed-files/tags?after=v…
56
comments
Opened 3 other issues in 3 repositories
FuelLabs/fuels-wallet
1
open
-
Using a compromised tj-actions/changed-files GitHub Action
This contribution was made on Mar 17
ArmDeveloperEcosystem/arm-learning-paths
1
closed
-
Using a compromised tj-actions/changed-files GitHub Action
This contribution was made on Mar 17
varunsh-coder/test
1
open
-
markdown
This contribution was made on Mar 14