Notifications
Tenant-level notification settings control how your tenant is alerted when StepSecurity threat intelligence flags a compromised component. Channels configured here apply tenant-wide, across every organization connected to the tenant.
For notification settings scoped to a single organization, including Harden-Runner detections, GitHub Checks results, and workflow run policies, see Notifications under Organization Settings.
Accessing tenant notification settings
Open the StepSecurity dashboard and click Back to Dashboard if you are inside an organization view.
In the Admin console left menu, expand Settings.
Click Notifications.

Notification Channels
These are the tenant-wide channels used for threat intel notifications. Configure one or more of the following:
Email address that receives threat intel notifications.
Slack Webhook URL
Slack incoming webhook, in the form https://hooks.slack.com/services/.... Follow these instructions to create a Slack webhook.
Teams Webhook URL
Microsoft Teams incoming webhook. Follow these instructions to create a Teams webhook.
Notification Events
Under Notification Events, select Notify when StepSecurity threat intel flags a compromised component to get notified about components flagged by StepSecurity threat intel.
Threat intel notifications cover the same incidents surfaced in the Threat Center. Each incident identifies the compromised packages or Actions involved and the recommended remediation steps.
Choosing threat intel notification granularity
Once the event is enabled, open the Threat intel notifications dialog to choose when this tenant is notified:

All threat intel incidents
Notify about every threat intel incident, whether or not this tenant is affected.
Affected packages
Notify only when this tenant is affected by a compromised package, matched by name, at any version.
Exact version only
Notify only when this tenant has the exact compromised version installed.
Choose All threat intel incidents if your security team tracks ecosystem-wide threats regardless of exposure. Choose Affected packages or Exact version only to reduce alert volume to incidents that touch your own dependencies, with Exact version only producing the narrowest set of alerts.
Click Done to confirm your selection.
Saving your changes
Click Save to apply your channel and event configuration. Changes take effect for incidents raised after saving.
Last updated
Was this helpful?