Security
In-depth guides and analysis on security from the Safeguard engineering team.
521 articles
Rego Policy Examples: Practical Rules for Policy-as-Code
Real Rego policy examples you can adapt today — from denying privileged containers to gating deployments on vulnerability severity — with the language patterns that make them readable.
spring-webmvc Security: Known CVEs and How to Stay Patched
A security guide to the spring-webmvc Maven dependency: recent path traversal CVEs, affected version ranges, and how to keep this core Spring artifact patched.
@typescript-eslint/typescript-estree: A Security Review
A security review of @typescript-eslint/typescript-estree: what the parser does, where its real risk lives (its dependencies, not itself), and how to keep it safe.
Installing a Java Runtime on Mac the Secure Way
The safest way to install a Java runtime on Mac is a maintained OpenJDK build like Temurin via Homebrew. Here is how to do it on Apple Silicon and avoid licensing and update traps.
Has AWS Ever Been Hacked? What 'AWS Hacked' Headlines Really Mean
When people ask 'has AWS ever been hacked,' the honest answer is that AWS infrastructure has not been breached, but AWS customers get breached constantly through their own misconfigurations. Here is the difference and why it matters.
PHP Webshells: How Attackers Plant Them and How to Detect One
A PHP webshell is a malicious script that gives an attacker remote control of your server. Here is how they get planted, what they look like, and how to find them.
Who Is the CEO of Snyk, and Why It Matters for Buyers
The Snyk CEO question comes up during vendor evaluations for a reason: leadership shapes roadmap and stability. Here is who runs Snyk and how to read leadership signals as a buyer.
DevOps Performance Metrics That Also Measure Security
The DevOps performance metrics worth tracking are the four DORA metrics plus a handful of security signals that reveal whether speed is coming at the cost of risk.
Malware Code Explained: How Malicious Code Works and How to Detect It
Malware code is any code written to run without the owner's informed consent and against their interest. Understanding its patterns is what makes it detectable.
What Goes Into a Product Security Engineer Job Description (and What It Pays)
A realistic product security engineer job description: the actual responsibilities, the skills that matter, how the role differs from AppSec, and what the salary looks like.
JavaScript Not Equal (!= vs !==): Why the Wrong One Is a Security Bug
The JavaScript not equal operators != and !== look interchangeable but aren't. Loose comparison triggers type coercion that has caused real auth bypasses. Here's how to compare safely.
CVE-2021-3918: Prototype Pollution in json-schema Explained
CVE-2021-3918 is a prototype pollution vulnerability in the json-schema npm package that can let crafted input tamper with JavaScript object prototypes. Here is who is affected and how to fix it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.