Safeguard
Topic

DevSecOps

In-depth guides and analysis on devsecops from the Safeguard engineering team.

100 articles

DevSecOps

CI Secret Masking Matches the Exact String, and Almost Nothing Else

Encode it, uppercase it, split it across two log lines, and masking has nothing to match against. This is not a bug in any platform. It is the only mechanism possible without semantic analysis of every command a pipeline runs.

Sep 18, 20266 min read
DevSecOps

A Required Approval Proves a Button Was Clicked, Not That Anyone Read the Code

Branch protection requires review before merge. Your audit evidence shows one on every pull request for a year. It does not show whether any of them involved a person reading the diff, and for a meaningful share, they did not.

Sep 18, 20266 min read
DevSecOps

You Tested a Different Artefact Than the One You Shipped

Tests pass against a build with debug assertions, development dependencies and verbose errors. You then ship something compiled differently, with a different dependency set, that behaves differently when something goes wrong.

Sep 18, 20265 min read
DevSecOps

A Self-Hosted Runner Is a Machine on Your Network That Runs Strangers' Code

A hosted runner is destroyed after the job. A self-hosted one persists, on your network, executing code from your repository, and if that repository accepts contributions the code is not always yours.

Sep 18, 20265 min read
DevSecOps

Which Changes Should Trigger a Security Review

Asking developers to involve security when it seems relevant fails in both directions, because relevance requires exactly the expertise the person does not have. Give them observable properties instead.

Sep 18, 20265 min read
DevSecOps

The Service Template Is the Highest-Leverage Control You Will Build

One security engineer cannot review every service a hundred developers write. What works is deciding things once, in a scaffold, so every service created afterwards starts with those decisions already made.

Sep 18, 20266 min read
DevSecOps

A Feature Flag That Disables a Control Is a Control You Do Not Have

Added during an incident to skip a validation or bypass a limit, intended to be reverted that afternoon, and nothing reminds anyone. It lives in a system with weaker access control and no change record than your permission model.

Sep 18, 20266 min read
DevSecOps

Your ChatOps Bot Is an Admin API Nobody Reviewed

It deploys, restarts, queries production and rotates keys, and the authorization check is whether the person is in the channel. It became powerful one useful command at a time, and none of them got the review a new admin API would have.

Sep 18, 20266 min read
DevSecOps

When Automated Agents Share One Deploy Lock

Three agents, one lock, every one of them correct in isolation. The service restarts every few minutes for an hour and there is no bug to find, because the harmful behaviour only exists in aggregate.

Sep 17, 20266 min read
DevSecOps

Is It Working or Is It Stuck? Long-Running Jobs Need a Progress Signal

CPU, connection counts, process liveness and log volume are all proxies that decouple from reality in exactly the case you are trying to detect. One timestamp fixes it: when the last unit of work completed.

Sep 17, 20266 min read
DevSecOps

Your CI Job Is Not Hung, It Is Slower Than Your Timeout

A timeout kills a process and loses its buffered output, so a suite that needed eleven minutes looks exactly like a deadlock. How to tell them apart, the defaults that catch people, and why a killed scan must never count as a pass.

Sep 17, 20266 min read
DevSecOps

The Dockerfile in Your Repository Is Probably Not What Builds

An urgent fix gets made on the build host, the backport never happens, and the repository copy becomes a historical document. Absent files prompt questions; stale ones answer them wrongly.

Sep 17, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.