Security
In-depth guides and analysis on security from the Safeguard engineering team.
521 articles
What Is a DTO (Data Transfer Object)? Security Notes for Java and Beyond
A DTO is a plain object that carries data across a boundary. Used well it is also one of your best defenses against mass assignment and data over-exposure.
The Snyk Logo: The Story Behind Patch the Guard Dog
The Snyk logo is a friendly Doberman named Patch, and the choice of a guard dog says more about the company's positioning than a wordmark ever could.
Vulnerability Meaning in Telugu: The Term Explained for Security Teams
The vulnerability meaning in Telugu is durbalatvam, a weakness that can be exploited. Here is the translation plus what the word actually signifies in software security.
@testing-library/jest-dom: What It Does and How to Keep It Secure
@testing-library/jest-dom is a dev-only matcher library that is low risk to your production security, provided you keep it out of your runtime bundle and patched.
CVE-2023-22081: The Oracle Java JSSE Denial-of-Service Flaw
CVE-2023-22081 is a Java SE and GraalVM vulnerability in the JSSE component that can cause a partial denial of service over HTTPS. Here is what to patch.
CVE-2022-40152: Woodstox XML Parsing Denial of Service
CVE-2022-40152 lets malicious XML with deeply nested DTD content crash Woodstox-based parsers via stack overflow. Here is the root cause, affected versions, and how to remediate it.
What Is Snyk Code? A Guide to the SAST Often Misspelled "Synk Code"
"Synk Code" is a common misspelling of Snyk Code, Snyk's developer-first SAST engine. Here is what it scans, how DeepCode AI works, and where it fits.
Secure Session Management: A Practical Guide for Web Apps
Secure session management comes down to a handful of decisions about cookies, storage, expiry, and rotation. Get those right and you close off most session-based attacks.
How to Choose an Enterprise Vulnerability Management Tool
What an enterprise vulnerability management tool actually needs to do, how it differs from a scanner, and the evaluation criteria that separate a program that scales from one that drowns in noise.
PHP Application Security: A Practical Guide to Locking Down Your Code
PHP application security comes down to a handful of high-impact controls. Here is how to handle injection, sessions, uploads, and dependencies without the theory.
Spring Boot Logging Best Practices That Keep Secrets Out of Your Logs
Spring Boot logging best practices focused on security: structured logs, keeping secrets and PII out, safe log levels, and avoiding the mistakes that turned Log4Shell into a catastrophe.
The Semgrep Logo and What Semgrep Actually Does
Looking for the Semgrep logo often means you are evaluating Semgrep the tool. Here is what the brand mark represents and how the static analysis engine works.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.