Safeguard
Topic

Security

In-depth guides and analysis on security from the Safeguard engineering team.

521 articles

Security

How Is DevOps Delivery Value Measured?

How DevOps delivery value is measured in practice: the four DORA metrics, why security belongs in the picture, and the traps that make the numbers lie.

Oct 8, 20257 min read
Security

Capture the Flag Cyber Security: How CTF Games Work

Capture the flag cyber security competitions turn real security skills into a game where you find hidden flags by breaking, analyzing, and defending systems. Here is how they work and why they build practitioners.

Oct 8, 20256 min read
Security

Snyk and Log4j: Finding and Fixing Log4Shell in Your Dependencies

Snyk can detect the Log4Shell family of Log4j vulnerabilities across your dependency tree, including transitive ones. Here is what it finds, how the fix path works, and the limits to know.

Oct 8, 20255 min read
Security

Snyk Docs: A Practical Guide to Finding What You Need

The Snyk docs at docs.snyk.io cover four scanning products and a maze of integrations. Here's how they're organized and the fastest path to the page you actually want.

Oct 7, 20256 min read
Security

Trivy vs Snyk: A Practical Comparison for Real Pipelines

Trivy vs Snyk is really open-source scanner versus commercial platform. Here is where each wins, where they overlap, and why many teams run both.

Oct 7, 20256 min read
Security

How to Choose a Vulnerability Assessment Solution

A vulnerability assessment solution finds, ranks, and tracks weaknesses across your systems. Here is what separates a useful one from a report generator.

Oct 6, 20255 min read
Security

Source Code Protection: How to Keep Your Codebase From Leaking

Source code protection is less about obfuscation and more about controlling access, catching secrets before they leak, and knowing when your code has escaped. Here is how to do it.

Oct 5, 20256 min read
Security

JavaScript DI: Dependency Injection Patterns and Their Security Impact

JavaScript DI (dependency injection) decouples your code, but the container that wires it together is also a place security can slip. Here is how to use it well.

Oct 5, 20256 min read
Security

The AGPL Licence Explained: Obligations and Real Risks

The AGPL licence closes the SaaS loophole in the GPL by triggering source-sharing over the network. Here is what it obliges, and where it bites teams by surprise.

Oct 5, 20256 min read
Security

Cloud Audit: How to Audit Your Cloud Environment for Security

A cloud audit is a systematic review of your cloud accounts against security and compliance baselines. Here is a practical process covering identity, configuration, logging, and evidence.

Oct 5, 20256 min read
Security

Snyk Valuation: How Much Is Snyk Worth?

Snyk's valuation peaked at $8.5 billion in 2021, then repriced through later rounds and investor markdowns. Here is the documented timeline and what it signals.

Oct 3, 20255 min read
Security

Threat Model Examples: Walkthroughs You Can Actually Copy

Concrete threat model examples for a web app, an API, and a CI/CD pipeline, using STRIDE and data flow diagrams to show how the process works end to end.

Oct 2, 20256 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Security (Page 5) — Supply Chain Security Blog | Safeguard