Safeguard
Topic

Security

In-depth guides and analysis on security from the Safeguard engineering team.

521 articles

Security

dom-to-image-more: Using the DOM-to-Image Fork Safely

dom-to-image-more turns a DOM node into a PNG, JPEG, or SVG in the browser. What the fork fixes, and the security considerations when rendering user content.

Jun 19, 20255 min read
Security

How to Choose an Application Security Company

What an application security company actually does, the categories of vendors, and the questions that separate real coverage from a dashboard full of noise.

Jun 19, 20257 min read
Security

Which Ethical Hacking Tools Should Your Security Team Actually Use?

Ethical hacking tools help defenders find weaknesses before attackers do. Here is a practitioner's map of the categories, the well-known tools in each, and how to use them responsibly.

Jun 18, 20256 min read
Security

Enterprise Security Tools: What Actually Belongs in Your Stack

Enterprise security tools span identity, endpoint, network, application, and data layers. Here is a practical map of what each category does and how to avoid buying overlap.

Jun 18, 20256 min read
Security

MySQL Vulnerabilities: Common Risks and How to Patch Them

MySQL vulnerabilities range from privilege-escalation flaws in the server to injection and misconfiguration in the apps that use it. Here is what to watch and how to close the gaps.

Jun 18, 20256 min read
Security

Synk Artinya: What Snyk Means and Does

Synk artinya apa? A plain explanation of what Snyk is, what the tool does, how its pricing works, and where it fits in a security toolchain.

Jun 18, 20255 min read
Security

What a Website Security Checker Really Checks

A website security checker scans a site for exposed vulnerabilities, misconfigurations, and known-bad dependencies. Here is what it catches and where it stops.

Jun 16, 20256 min read
Security

Lodash 4.17.21 Vulnerabilities: What the 'Safe' Version Still Misses

Lodash 4.17.21 was the release that fixed the famous prototype pollution and command injection bugs. Here is what it patched and why it is no longer the final word.

Jun 16, 20255 min read
Security

What Makes a Good Open Source Security Platform?

An open source security platform has to cover the whole dependency lifecycle, not just print CVEs. Here is what the category actually includes and how to evaluate one for your stack.

Jun 16, 20256 min read
Security

Cloud Insight: Turning Cloud Telemetry Into Security Signal

Cloud insight is the practice of turning raw cloud logs, configs, and inventory into decisions you can act on. Here is how to build it without drowning in dashboards.

Jun 15, 20256 min read
Security

The Core Pillars of DevSecOps, Explained

The DevSecOps pillars are the recurring foundations every mature program shares: culture, automation, shift-left testing, continuous monitoring, and shared measurement.

Jun 15, 20256 min read
Security

Cloud Insights for Kubernetes Security: What They Actually Tell You

Cloud insights turn raw telemetry from your clusters and cloud accounts into security signals you can act on. Here is how to read them for Kubernetes.

Jun 14, 20256 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Security (Page 18) — Supply Chain Security Blog | Safeguard