StepSecurity has released a new API endpoint for its Threat Center that returns compromised OSS components for any supply chain incident. The endpoint (GET /github/{owner}/threat-intel/incidents/{incidentId}/compromised-components) provides structured data including package ecosystem, affected version, severity, verification status, and threat description. Teams can use it to automate incident response, enrich SIEM workflows with typed component data, and cross-reference incidents against their own SBOM or lockfiles to quickly determine exposure. The feature is available to StepSecurity Enterprise customers and integrates with existing detection events, webhook/S3 integrations, and the Secure Registry.

5m read timeFrom stepsecurity.io
Post cover image
Table of contents
Where this fitsWhat the endpoint doesThree ways teams can use itThe bigger pictureGetting started
84 Impressions