Security
In-depth guides and analysis on security from the Safeguard engineering team.
521 articles
Snyk Jobs: What a Career in Developer Security Looks Like
Curious about Snyk jobs and roles in the developer-security space? Here is how the field is structured, the skills that get you hired, and what to expect.
CVE-2021-3331: How the WinSCP URL Handler RCE Works
CVE-2021-3331 is a critical remote code execution flaw in WinSCP's URL handling before 5.17.10. Here is how a crafted link triggers it and how to fix it.
CVSS Full Form: What Does CVSS Stand For?
The CVSS full form is Common Vulnerability Scoring System. Here is what the acronym means, how the 0-10 score is built, and how to use it without treating the number as gospel.
How Can a DevOps Team Take Advantage of Artificial Intelligence?
A DevOps team takes advantage of artificial intelligence by using it where signal is buried in noise — triaging alerts, prioritizing vulnerabilities, and drafting fixes. Here is where it pays off and where it does not.
Choosing a Software Composition Analysis Tool: A Practical Guide
A software composition analysis tool inventories your open-source dependencies and flags the vulnerable ones. Here is how it differs from static code analysis and how to pick one.
A Threat Modeling Example, Walked Through Step by Step
A concrete threat modeling example beats any amount of theory. We model a real feature, a file-upload API, with STRIDE and turn the findings into fixes.
eslint-import-resolver-typescript: A Security Guide
eslint-import-resolver-typescript lives in your dev toolchain, which is precisely the part of the supply chain attackers now target. Here is how to keep it clean.
GPLv2 vs GPLv3: A Practical Comparison for Developers
The real differences between GPLv2 and GPLv3 that affect how you ship software: patents, tivoization, license compatibility, and the security angle.
SFMC API Security: How to Integrate Marketing Cloud Safely
A security-focused guide to the Salesforce Marketing Cloud (SFMC) API: OAuth scopes, token handling, least-privilege packages, and protecting subscriber data.
Rate Limiting Vulnerability: Why Missing Limits Are an OWASP Risk
A rate limiting vulnerability lets attackers hammer your endpoints unchecked, enabling brute force, credential stuffing, and resource exhaustion. Here is how to find and fix it.
Using a Code Tester Safely: Online Playgrounds and the Risks
An online code tester is a fast way to run a snippet without local setup, but pasting real code into someone else's server carries real risk. Here is how to test code online without leaking secrets.
GPL Adalah: What the GNU General Public License Means for Your Code
GPL adalah lisensi copyleft yang paling terkenal. This guide explains what the GPL actually requires, why the copyleft obligation matters, and how it affects the code you ship.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.