DevSecOps
In-depth guides and analysis on devsecops from the Safeguard engineering team.
497 articles
DevOps Pipeline Tools: A Buyer's Map by Stage
DevOps pipeline tools cluster around six stages of the software lifecycle — mapping a shortlist to the stage it actually serves prevents the most common buying mistake: overlap without coverage.
Environment Variable Injection in CI/CD Pipelines
Environment variables in CI/CD systems carry secrets, configuration, and control flow. When attackers can inject or modify them, everything breaks.
SLSA v1.0: Supply-chain Levels for Software Artifacts Reaches Maturity
SLSA v1.0 simplifies the framework and makes it practical to adopt. Here's what changed and how to implement it.
How to Pin GitHub Actions to SHAs Correctly
A hands-on guide to pinning every third-party GitHub Action to a full commit SHA, automating updates with Dependabot, and avoiding the common pitfalls.
GitLab CI/CD Security Configuration
Hardening GitLab CI/CD pipelines with protected variables, secure runners, and built-in security scanning.
Software Attestation in Practice: From Theory to Implementation
Software attestation is moving from academic concept to practical requirement. Here's how to implement it in your build pipelines today.
Chaos Engineering for Supply Chain Resilience: Breaking Your Build to Make It Stronger
Chaos engineering principles applied to the software supply chain reveal hidden dependencies, single points of failure, and degradation paths that only surface under stress.
What is a CI/CD Pipeline
A CI/CD pipeline automates code from commit to deployment—but SolarWinds, Codecov, and CircleCI show it's also a top supply-chain attack target.
3CX Attack Lessons: What Every Software Vendor Must Do Differently
The 3CX supply chain attack exposed critical gaps in how software vendors protect their build pipelines. Here are the concrete lessons.
GitLab CI Security Scanning Setup
Step-by-step guide to enabling SAST, DAST, dependency scanning, and container scanning in GitLab CI pipelines.
GitHub Actions: SHA-Pin Tags or Get Burned
Tag-pinning Actions feels fine until a maintainer gets compromised. Here is why SHA-pinning is the only serious option in 2026 and how to operationalize it.
Ruby Brakeman Security Scanner: Rails-Aware Vulnerability Detection
Brakeman understands Rails conventions and catches security issues that generic scanners miss. Here is how to use it effectively.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.