Engineering
In-depth guides and analysis on engineering from the Safeguard engineering team.
29 articles
Silent Configuration Drift Between Environments
A feature flag left on in staging and off in production, an environment variable raised during an incident and never reverted, a database-backed setting edited by hand. None of these show up in a code diff, and each one is a way two environments that are supposed to be identical quietly stop being identical.
Git Ancestry Lies About Whether Work Shipped
A commit hash derives from its parents, so a rewrite gives identical changes new identities. is-ancestor answers graph position, not whether the change is present, and squash merges put most teams in this state permanently.
A Container Stuck on health: starting Is Probably a Crash Loop
Each restart resets the health check, so a crash loop and a slow boot look identical in the status column. The one command that tells them apart, and the merge conflict class that produces the most convincing version.
Four Ways a Java Agent Instruments Nothing and Tells You It Worked
Class loader boundaries, a class literal that cannot resolve, advice read as a resource, and a re-entrancy guard that sticks. All four produce an agent that attaches cleanly and finds nothing.
A 200 Does Not Prove the Page Is Reading Your CMS
We moved a few hundred pages from committed files into a content API. Every page returned 200 throughout, including the four things we broke. What to assert instead of status.
Terraform Module Supply Chain Security
The dependency lockfile everyone commits only covers providers — your modules float free. Pinning, provenance, and the code-execution paths hiding inside terraform plan.
Reproducible Builds: Why Bit-for-Bit Identical Matters
If two builds of the same source produce different binaries, you cannot prove what you shipped. How determinism breaks, the flags that fix it, and why auditors care.
Securing the .NET NuGet Supply Chain
Package source mapping, packages.lock.json, NuGetAudit and signature verification — .NET ships more built-in supply chain controls than any other ecosystem. Most teams enable none of them.
Homebrew Formula Security for Engineering Teams
Every brew install runs Ruby you didn't read on a laptop that holds your SSH keys and cloud credentials. How formulae, taps, casks and bottles actually differ in risk.
Insider Threats in Open Source Projects: Lessons from XZ Utils
The XZ Utils backdoor was a three-year social engineering operation, not a coding mistake. What the timeline shows about maintainer trust, and what you can actually monitor.
Securing GitHub Actions Reusable Workflows at Scale
Reusable workflows centralize CI logic — and centralize compromise. Pinning, secrets scoping, org policy, and the review process that keeps one bad merge from owning 400 repos.
Java Supply Chain Security Beyond Log4Shell
Log4Shell was the fire drill. The structural problems — unverified Maven resolution, invisible shaded jars, sprawling transitive graphs — are still there. Here's what to actually fix.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.