Safeguard
Topic

Security

In-depth guides and analysis on security from the Safeguard engineering team.

521 articles

Security

CVE-2022-37601: Prototype Pollution in loader-utils Explained

CVE-2022-37601 is a prototype pollution flaw in the webpack loader-utils package. Here is what it affects, how it works, and how to remediate it.

May 22, 20255 min read
Security

CVE-2023-36665: The protobuf.js Prototype Pollution Vulnerability Explained

CVE-2023-36665 is a critical prototype pollution flaw in protobuf.js that can lead to remote code execution. Here is how it works and how to fix it fast.

May 22, 20255 min read
Security

Fix My Java Code: A Practical Guide to Finding and Fixing Security Bugs

"Fix my Java code" usually means a security or dependency problem. Here is a repeatable way to find the real fault, fix it, and stop it from returning.

May 22, 20256 min read
Security

What Gartner Says About DevSecOps: Tools, Trends, and How to Read the Guidance

Gartner's DevSecOps research shapes a lot of security budgets. Here is how to interpret the guidance without buying every category on the map.

May 22, 20255 min read
Security

JavaScript Exploits Explained: How They Work and How to Stop Them

A practitioner's tour of the JavaScript exploit classes that actually break production apps — prototype pollution, XSS, and malicious dependencies — with detection and fixes.

May 22, 20257 min read
Security

What Does the DevSecOps Acronym Actually Mean?

The DevSecOps acronym stands for Development, Security, and Operations, describing a practice that folds security into the software delivery pipeline rather than bolting it on at the end.

May 22, 20256 min read
Security

What a Security Testing Service Does and When You Need One

A security testing service systematically probes your applications and infrastructure for weaknesses before attackers do. Here is what the different types cover and how to choose.

May 22, 20256 min read
Security

Code Quality Software and Security: Where Clean Code and Safe Code Overlap

Code quality software catches more security bugs than most teams give it credit for. Here is how quality tooling and security tooling overlap, where they diverge, and how to combine them.

May 20, 20255 min read
Security

Password Validation: How to Verify Credentials Securely

Password validation is more than a regex for length and symbols. Here is how to check credentials the way modern guidance actually recommends.

May 20, 20256 min read
Security

How Do You Pronounce Snyk? The Definitive Answer

Snyk is pronounced sneak, like the verb. Here is where the name comes from, why people get it wrong, and what the tool actually does.

May 20, 20255 min read
Security

SQLi Cheat Sheet: Detection and Defense Guide

A practical SQLi cheat sheet covering how injection works, the patterns to recognize, and the parameterized-query defenses that actually stop it.

May 20, 20256 min read
Security

What Is the Definition of Malicious Code?

Malicious code is any software or script written to damage, disrupt, or gain unauthorized access to a system. Here is a precise definition and the main categories.

May 20, 20256 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Security (Page 24) — Supply Chain Security Blog | Safeguard