StepSecurity Logo
StepSecurity
    • Get Started

    • Overview

    • Threat Center

      • Workflow Runs

      • Baseline

      • Detections

      • Suppression Rules

      • Policy Store

      • Self Hosted Runners

    • Action Secrets

    • Apps & PATs

  • Settings

  1. compromised-packages
  2. Analyze Malicious Setup-Trivy Commit

Jobs

  • analyze

analyze

Harden-runner policy:
audit
Start time:20 Mar 2026 02:24:15 GMTRunner name:-Duration:19sJob labels:ubuntu-latest
Show:
Show all steps
StepPIDProcessDestinationPortStatus
Run malicious setup-trivy commitaquasecurity/setup-trivy@8afa9b9f9183b4e00c46e2b82d34047e3c177bd0
2849curlscan.aquasecurtiy.orgAPI Calls1443AllowedNot in baseline - learning20 Mar 2026 02:24:27
Run malicious setup-trivy commitaquasecurity/setup-trivy@8afa9b9f9183b4e00c46e2b82d34047e3c177bd0
3009curlGitHubgithub.comAPI Calls1443AllowedNot in baseline - learning20 Mar 2026 02:24:29
Run malicious setup-trivy commitaquasecurity/setup-trivy@8afa9b9f9183b4e00c46e2b82d34047e3c177bd0
3021curlget.trivy.devAPI Calls1443AllowedNot in baseline - learning20 Mar 2026 02:24:29
Run malicious setup-trivy commitaquasecurity/setup-trivy@8afa9b9f9183b4e00c46e2b82d34047e3c177bd0
3021curlGitHubrelease-assets.githubusercontent.comAPI Calls1443AllowedNot in baseline - learning20 Mar 2026 02:24:29
Run malicious setup-trivy commitaquasecurity/setup-trivy@8afa9b9f9183b4e00c46e2b82d34047e3c177bd0
2962git-remote-httpGitHubgithub.comAPI Calls1443AllowedNot in baseline - learning20 Mar 2026 02:24:28