Security
In-depth guides and analysis on security from the Safeguard engineering team.
521 articles
Checkmarx Careers: What a Career in Application Security Involves
Curious about Checkmarx careers or breaking into AppSec generally? Here is what these roles actually involve, the skills that matter, and how to prepare.
How Application Security Risk Management Actually Works in Practice
A working model for application security risk management: how to inventory assets, rate risk you can act on, prioritize by exploitability and impact, and prove the program is reducing risk.
Risk Management Applications: How to Secure the Tools You Rely On
Risk management applications concentrate your most sensitive data, which makes them a target. Here is how to think about securing the software that manages your risk.
What Is Memory Management? A Security-Focused Explainer
Memory management is how a program allocates and frees memory, and getting it wrong is the root of some of the most exploited vulnerability classes in software.
Snyk Advisor: What It Is and How to Read Its Score
Snyk Advisor is a free package health tool that rates open source packages from 0 to 100 across popularity, maintenance, security, and community. Here is how to use it well.
How to Choose a Security Company for Modern Software
Picking a security company is less about brand recognition than about matching a vendor's real strengths to the risks your software actually faces. Here is a practical way to decide.
What Is a Code Checker? A Security-Focused Guide
A code checker analyzes source for bugs, style issues, and security flaws before they ship. Here is how the security-relevant ones work, with a focus on Java.
Snyk Enso: How the Enso Security Acquisition Added ASPM
Snyk acquired Enso Security in 2023 to fold application security posture management into its platform. Here is what Enso did, what changed, and how to think about ASPM.
Licence logicielle : le guide securite et conformite
Ce qu'est une licence logicielle, pourquoi elle constitue un risque de securite et de conformite dans vos dependances open source, et comment la gerer concretement.
CVE-2023-4641: The shadow-utils Password Leak Explained
CVE-2023-4641 is an information-disclosure flaw in shadow-utils where a failed password change can leave the entered password lingering in memory. Here is who is affected and how to remediate it.
Apache Licence Explained: What the Apache 2.0 Licence Means for Your Code
The Apache licence is permissive but not effortless. Here is what Apache 2.0 actually requires — the patent grant, the NOTICE file, and where it clashes with GPL.
PHP Code Analyzer Tools: A Security Guide
A PHP code analyzer inspects your source without running it to catch security flaws, type errors, and bad patterns. Here's how static analysis fits a secure PHP workflow and which tools matter.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.