Safeguard
Topic

Engineering

In-depth guides and analysis on engineering from the Safeguard engineering team.

29 articles

Engineering

Silent Configuration Drift Between Environments

A feature flag left on in staging and off in production, an environment variable raised during an incident and never reverted, a database-backed setting edited by hand. None of these show up in a code diff, and each one is a way two environments that are supposed to be identical quietly stop being identical.

Sep 18, 20266 min read
Engineering

Git Ancestry Lies About Whether Work Shipped

A commit hash derives from its parents, so a rewrite gives identical changes new identities. is-ancestor answers graph position, not whether the change is present, and squash merges put most teams in this state permanently.

Sep 17, 20266 min read
Engineering

A Container Stuck on health: starting Is Probably a Crash Loop

Each restart resets the health check, so a crash loop and a slow boot look identical in the status column. The one command that tells them apart, and the merge conflict class that produces the most convincing version.

Sep 17, 20266 min read
Engineering

Four Ways a Java Agent Instruments Nothing and Tells You It Worked

Class loader boundaries, a class literal that cannot resolve, advice read as a resource, and a re-entrancy guard that sticks. All four produce an agent that attaches cleanly and finds nothing.

Sep 17, 20266 min read
Engineering

A 200 Does Not Prove the Page Is Reading Your CMS

We moved a few hundred pages from committed files into a content API. Every page returned 200 throughout, including the four things we broke. What to assert instead of status.

Sep 17, 20266 min read
Engineering

Terraform Module Supply Chain Security

The dependency lockfile everyone commits only covers providers — your modules float free. Pinning, provenance, and the code-execution paths hiding inside terraform plan.

Aug 5, 20266 min read
Engineering

Reproducible Builds: Why Bit-for-Bit Identical Matters

If two builds of the same source produce different binaries, you cannot prove what you shipped. How determinism breaks, the flags that fix it, and why auditors care.

Jul 29, 20266 min read
Engineering

Securing the .NET NuGet Supply Chain

Package source mapping, packages.lock.json, NuGetAudit and signature verification — .NET ships more built-in supply chain controls than any other ecosystem. Most teams enable none of them.

Jul 25, 20266 min read
Engineering

Homebrew Formula Security for Engineering Teams

Every brew install runs Ruby you didn't read on a laptop that holds your SSH keys and cloud credentials. How formulae, taps, casks and bottles actually differ in risk.

Jul 16, 20266 min read
Engineering

Insider Threats in Open Source Projects: Lessons from XZ Utils

The XZ Utils backdoor was a three-year social engineering operation, not a coding mistake. What the timeline shows about maintainer trust, and what you can actually monitor.

Jul 13, 20266 min read
Engineering

Securing GitHub Actions Reusable Workflows at Scale

Reusable workflows centralize CI logic — and centralize compromise. Pinning, secrets scoping, org policy, and the review process that keeps one bad merge from owning 400 repos.

Jun 17, 20266 min read
Engineering

Java Supply Chain Security Beyond Log4Shell

Log4Shell was the fire drill. The structural problems — unverified Maven resolution, invisible shaded jars, sprawling transitive graphs — are still there. Here's what to actually fix.

Jun 8, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.