Security
In-depth guides and analysis on security from the Safeguard engineering team.
521 articles
Who Is Snyk's General Counsel, and Why Vendor Legal Governance Matters
The Snyk general counsel runs legal, privacy, and regulatory affairs for a developer security vendor. Here's what that role tells you about evaluating any security supplier.
oidc-client-ts: A Security Guide for Browser OIDC
oidc-client-ts is the maintained TypeScript library for adding OpenID Connect and OAuth2 to browser apps. Here is how to use it, and how to avoid the token-handling mistakes that undo its security.
Snyk Revenue Explained: ARR, Valuation, and the Road to IPO
Snyk revenue crossed $300M in annual recurring revenue with a $7.4B valuation. Here is what the numbers say about the developer-security market.
@aws-sdk/client-s3: A Practical Security Guide
The @aws-sdk/client-s3 package is the AWS SDK for JavaScript v3 S3 client. Here is how to use it securely, from credential handling to why v2 is now end-of-support.
spring-expression Security: SpEL Risks and How to Contain Them
What the spring-expression library does, the SpEL vulnerability classes it introduces, the 2026 SpEL CVEs, and how to evaluate expressions without opening an RCE or DoS hole.
What Is the HSTS Header and How Do You Configure It?
The HSTS header forces browsers to talk to your site over HTTPS only. Here is what Strict-Transport-Security does, how to set it safely, and why scanners like Checkmarx flag it as missing.
How Secure Is js-cookie? A Practical Security Guide
js-cookie is a tiny, popular cookie helper, but a 2026 attribute-injection flaw shows why the library needs the same scrutiny as any other dependency. Here is what to watch.
Security Testing Tools for Mobile Applications: What Actually Finds Bugs
A practitioner's guide to the security testing tools for mobile applications that matter — SAST, DAST, dependency scanning, and runtime instrumentation — and how to combine them without drowning in noise.
Checkmarx Pricing: What It Costs and How the Model Works
Checkmarx pricing is quote-based and not published publicly, driven by developer count, modules, and contract term. Here is what buyers actually report paying.
How to Write an Application Security Policy Teams Actually Follow
An application security policy only works if engineers can act on it. Here's how to write one that sets clear requirements, maps to real controls, and does not become shelfware.
Broken Access Control Examples: Real Cases and How to Fix Them
Broken access control is the number-one web risk on the OWASP Top 10. These examples show what it looks like in real code and how to close each gap.
JavaScript Security Vulnerabilities: The Ones That Actually Bite
JavaScript security vulnerabilities cluster around a few patterns: XSS, prototype pollution, ReDoS, and dependency risk. Here is how each works and how to catch it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.