Security
In-depth guides and analysis on security from the Safeguard engineering team.
521 articles
How Is DevOps Delivery Value Measured?
How DevOps delivery value is measured in practice: the four DORA metrics, why security belongs in the picture, and the traps that make the numbers lie.
Capture the Flag Cyber Security: How CTF Games Work
Capture the flag cyber security competitions turn real security skills into a game where you find hidden flags by breaking, analyzing, and defending systems. Here is how they work and why they build practitioners.
Snyk and Log4j: Finding and Fixing Log4Shell in Your Dependencies
Snyk can detect the Log4Shell family of Log4j vulnerabilities across your dependency tree, including transitive ones. Here is what it finds, how the fix path works, and the limits to know.
Snyk Docs: A Practical Guide to Finding What You Need
The Snyk docs at docs.snyk.io cover four scanning products and a maze of integrations. Here's how they're organized and the fastest path to the page you actually want.
Trivy vs Snyk: A Practical Comparison for Real Pipelines
Trivy vs Snyk is really open-source scanner versus commercial platform. Here is where each wins, where they overlap, and why many teams run both.
How to Choose a Vulnerability Assessment Solution
A vulnerability assessment solution finds, ranks, and tracks weaknesses across your systems. Here is what separates a useful one from a report generator.
Source Code Protection: How to Keep Your Codebase From Leaking
Source code protection is less about obfuscation and more about controlling access, catching secrets before they leak, and knowing when your code has escaped. Here is how to do it.
JavaScript DI: Dependency Injection Patterns and Their Security Impact
JavaScript DI (dependency injection) decouples your code, but the container that wires it together is also a place security can slip. Here is how to use it well.
The AGPL Licence Explained: Obligations and Real Risks
The AGPL licence closes the SaaS loophole in the GPL by triggering source-sharing over the network. Here is what it obliges, and where it bites teams by surprise.
Cloud Audit: How to Audit Your Cloud Environment for Security
A cloud audit is a systematic review of your cloud accounts against security and compliance baselines. Here is a practical process covering identity, configuration, logging, and evidence.
Snyk Valuation: How Much Is Snyk Worth?
Snyk's valuation peaked at $8.5 billion in 2021, then repriced through later rounds and investor markdowns. Here is the documented timeline and what it signals.
Threat Model Examples: Walkthroughs You Can Actually Copy
Concrete threat model examples for a web app, an API, and a CI/CD pipeline, using STRIDE and data flow diagrams to show how the process works end to end.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.