Open Source
In-depth guides and analysis on open source from the Safeguard engineering team.
252 articles
http-proxy-middleware on npm: Security Review and Safe Usage
http-proxy-middleware is a widely used npm proxy library that has shipped two notable CVEs. Here is what to pin, what to patch, and how to use it safely.
react-helmet-async: Is It Safe to Depend On in 2025?
react-helmet-async manages document head tags in React apps, but its maintenance history is bumpy. Here is what the package does, where the risk sits, and how to depend on it safely.
React Fast Marquee: A Security and Maintenance Guide
React Fast Marquee is a lightweight scrolling-marquee component for React. Here is an honest look at its risk profile, maintenance status, and how to use it safely.
react-native-fs: What to Know Before You Depend On It
react-native-fs gives React Native apps native filesystem access, but its maintenance status and the way you handle paths both carry real security weight.
npm classnames: Security Review and Safe Usage
The npm classnames package is a tiny, widely used utility for conditionally joining CSS class names. Here is its security profile and how to use it safely in React.
zipp in Python: Why It Is in Your Dependency Tree
The python zipp package shows up in almost every Python environment without ever being asked for by name. Here is what it does, how it got there, and the one CVE against it.
npm ssh2-sftp-client: Security Review and Safe Usage
ssh2-sftp-client wraps the ssh2 library in a promise-based SFTP API. Its security posture rests on host key verification and credential handling, which are easy to get wrong.
lint-staged (npm): A Security Review and Safe Setup Guide
The lint-staged npm package runs linters and formatters only on your git-staged files, keeping commits clean and fast. Here is how to configure it safely and what its command-running design means for security.
react-scripts After Create React App: A Security Guide
With Create React App deprecated, react-scripts is now in maintenance mode. Here is what that means for the security of projects still depending on it.
prop-types npm: Security Review and Safe Usage
The prop-types npm package is a runtime type checker React split out years ago. React 19 stopped honoring propTypes internally, which changes when and why you should still depend on it.
How Do You Create an npm Module Securely?
To create an npm module you need package.json, a clear entry point, and a publish step, but doing it safely means locking down metadata, tokens, and what actually ships. Here is the full walkthrough.
Is react-native-gesture-handler Safe? An npm Security Review
react-native-gesture-handler is a core, actively maintained library, but any native module changes your app's trust and update calculus. Here is the security review.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.