Security
In-depth guides and analysis on security from the Safeguard engineering team.
521 articles
Snyk in Boston: The Company Behind the Developer Security Tool
Snyk runs its headquarters out of Boston. Here is what the company does, where the office sits, and how developer-first security fits into a modern pipeline.
The Benefits of Rust: A Security Guide for Practitioners
Rust's biggest benefit is that it eliminates whole classes of memory-safety bugs at compile time. Here is what that means for security teams and where the limits are.
MTTR in DevOps: How to Measure and Actually Improve Recovery Time
MTTR is one of the four DORA metrics and the clearest signal of how resilient your delivery really is. Here is how to measure it honestly and drive it down.
Local Storage Security: What to Store and What Never To
Local storage security comes down to one rule most apps break: the browser's localStorage is readable by any JavaScript on the page, so it is no place for secrets.
What Is a Software Licence? A Plain-English Guide
A software licence is the legal agreement that defines how you may use, copy, modify, and distribute a piece of software. Here is how the main types differ and why it matters.
Gray Box Testing Explained: A Security Guide
Gray box testing gives a tester partial internal knowledge, splitting the difference between black box and white box. Here is when it finds bugs the other two miss.
What Is Linting in Code? A Security Perspective
Linting is automated static analysis that catches bugs, style issues, and security anti-patterns before code runs. Here is what it does and where it fits in a secure pipeline.
Statische Code-Analyse: Sicherheitsluecken finden, bevor Code laeuft
Statische Code-Analyse prueft Quellcode ohne ihn auszufuehren und findet Sicherheitsluecken frueh. So funktioniert sie und welche Tools sich lohnen.
Trivy Action: How to Use It in CI Without Getting Burned
The Trivy Action runs Aqua Security's scanner inside GitHub Actions. Here is how to wire it up, and why aquasecurity/trivy-action@master is the wrong way to pin it.
What Is a Cross-Site Scripting Vulnerability, and How Do You Fix It?
A cross-site scripting vulnerability lets an attacker run their JavaScript in your users' browsers, and you fix it by encoding output and validating input at the right boundaries.
GPL Meaning Explained: What the GNU General Public License Requires
GPL means GNU General Public License, a copyleft license that grants broad freedoms but requires you to share source under the same terms. Here is what that means for your code.
Code Quality Tools That Also Strengthen Your Security
Code quality tools do more than catch style nits; the good ones surface the same weak patterns that turn into vulnerabilities. Here is how quality tooling and security overlap, with a focus on Java.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.