For the complete documentation index, see llms.txt. This page is also available as Markdown.

Notifications

Tenant-level notification settings control how your tenant is alerted when StepSecurity threat intelligence flags a compromised component. Channels configured here apply tenant-wide, across every organization connected to the tenant.

For notification settings scoped to a single organization, including Harden-Runner detections, GitHub Checks results, and workflow run policies, see Notifications under Organization Settings.

Accessing tenant notification settings

  1. Open the StepSecurity dashboard and click Back to Dashboard if you are inside an organization view.

  2. In the Admin console left menu, expand Settings.

  3. Click Notifications.

Notification Channels

These are the tenant-wide channels used for threat intel notifications. Configure one or more of the following:

Field
Description

Email

Email address that receives threat intel notifications.

Slack Webhook URL

Slack incoming webhook, in the form https://hooks.slack.com/services/.... Follow these instructions to create a Slack webhook.

Teams Webhook URL

Microsoft Teams incoming webhook. Follow these instructions to create a Teams webhook.

Notification Events

Under Notification Events, select Notify when StepSecurity threat intel flags a compromised component to get notified about components flagged by StepSecurity threat intel.

Threat intel notifications cover the same incidents surfaced in the Threat Center. Each incident identifies the compromised packages or Actions involved and the recommended remediation steps.

Choosing threat intel notification granularity

Once the event is enabled, open the Threat intel notifications dialog to choose when this tenant is notified:

Option
Behavior

All threat intel incidents

Notify about every threat intel incident, whether or not this tenant is affected.

Affected packages

Notify only when this tenant is affected by a compromised package, matched by name, at any version.

Exact version only

Notify only when this tenant has the exact compromised version installed.

Choose All threat intel incidents if your security team tracks ecosystem-wide threats regardless of exposure. Choose Affected packages or Exact version only to reduce alert volume to incidents that touch your own dependencies, with Exact version only producing the narrowest set of alerts.

Click Done to confirm your selection.

Saving your changes

Click Save to apply your channel and event configuration. Changes take effect for incidents raised after saving.

Last updated

Was this helpful?