DevSecOps
In-depth guides and analysis on devsecops from the Safeguard engineering team.
497 articles
Mutable Tags Strike Again: actions-cool GitHub Action Tags Redirected to Imposter Commits (May 2026)
In May 2026, every tag on actions-cool/issues-helper and 15 tags on maintain-one-comment were quietly moved to point at imposter commits that stole CI/CD credentials from runner memory. A look at the mutable-tag attack class and how to defeat it.
CORS in Node.js: What It Is and How to Configure It Securely
CORS in Node.js trips up almost every developer at some point. Here is what CORS actually does, why you need it, and how to configure it without opening a hole.
Snyk Bitbucket Integration: Setup, Limits, and Alternatives
The Snyk Bitbucket integration comes in three distinct flavors — Cloud App, legacy Cloud, and Data Center — each with different capabilities. Setup steps and trade-offs.
tomcat-embed-core in Maven: A Security Guide to CVEs and Fixes
The tomcat-embed-core Maven artifact is the embedded Tomcat engine inside most Spring Boot apps, and it has carried several serious CVEs. Here is how to find your version and patch it.
False Positives vs False Negatives in Security Scanning
False positives in cyber security waste your team's time; false negatives get you breached. Here is how to think about the trade-off and tune for it deliberately.
Top 8 DevSecOps best practices
Log4Shell and the xz backdoor show why DevSecOps matters. Eight concrete practices — from reachability triage to auto-fix PRs — teams can implement now.
How to implement DevSecOps in 4 steps
A concrete, 4-step playbook for implementing DevSecOps — pipeline gating, SBOM generation, reachability-based triage, and auto-fix PRs.
DevSecOps automation: principles, frameworks, and tools
A practical breakdown of DevSecOps automation frameworks — principles, standards like NIST SSDF, and the tools that turn shift-left security into a repeatable pipeline.
The 4 best DevSecOps tools for a secure DevOps workflow
The 4 DevSecOps tool categories a secure pipeline needs — SCA, SAST, container/IaC scanning, secrets scanning — with real incidents and fixes.
Building a security-conscious CI/CD pipeline
CI/CD pipelines are now the top supply chain target. Here's how to build one with real controls—secrets, scoping, SBOMs, and provenance.
8 tips for securing your CI/CD pipeline
Real incidents like tj-actions and xz-utils show how CI/CD pipelines get compromised. Eight concrete, actionable tips to lock yours down.
Python pptx: Using python-pptx Securely to Build Presentations
python pptx usually means the python-pptx library for reading and writing PowerPoint files. Here is how it works and the security pitfalls of processing untrusted decks.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.