Safeguard
Topic

Security

In-depth guides and analysis on security from the Safeguard engineering team.

521 articles

Security

Who Is Snyk's General Counsel, and Why Vendor Legal Governance Matters

The Snyk general counsel runs legal, privacy, and regulatory affairs for a developer security vendor. Here's what that role tells you about evaluating any security supplier.

Sep 17, 20256 min read
Security

oidc-client-ts: A Security Guide for Browser OIDC

oidc-client-ts is the maintained TypeScript library for adding OpenID Connect and OAuth2 to browser apps. Here is how to use it, and how to avoid the token-handling mistakes that undo its security.

Sep 16, 20256 min read
Security

Snyk Revenue Explained: ARR, Valuation, and the Road to IPO

Snyk revenue crossed $300M in annual recurring revenue with a $7.4B valuation. Here is what the numbers say about the developer-security market.

Sep 16, 20256 min read
Security

@aws-sdk/client-s3: A Practical Security Guide

The @aws-sdk/client-s3 package is the AWS SDK for JavaScript v3 S3 client. Here is how to use it securely, from credential handling to why v2 is now end-of-support.

Sep 16, 20256 min read
Security

spring-expression Security: SpEL Risks and How to Contain Them

What the spring-expression library does, the SpEL vulnerability classes it introduces, the 2026 SpEL CVEs, and how to evaluate expressions without opening an RCE or DoS hole.

Sep 16, 20255 min read
Security

What Is the HSTS Header and How Do You Configure It?

The HSTS header forces browsers to talk to your site over HTTPS only. Here is what Strict-Transport-Security does, how to set it safely, and why scanners like Checkmarx flag it as missing.

Sep 16, 20257 min read
Security

How Secure Is js-cookie? A Practical Security Guide

js-cookie is a tiny, popular cookie helper, but a 2026 attribute-injection flaw shows why the library needs the same scrutiny as any other dependency. Here is what to watch.

Sep 16, 20257 min read
Security

Security Testing Tools for Mobile Applications: What Actually Finds Bugs

A practitioner's guide to the security testing tools for mobile applications that matter — SAST, DAST, dependency scanning, and runtime instrumentation — and how to combine them without drowning in noise.

Sep 16, 20257 min read
Security

Checkmarx Pricing: What It Costs and How the Model Works

Checkmarx pricing is quote-based and not published publicly, driven by developer count, modules, and contract term. Here is what buyers actually report paying.

Sep 15, 20255 min read
Security

How to Write an Application Security Policy Teams Actually Follow

An application security policy only works if engineers can act on it. Here's how to write one that sets clear requirements, maps to real controls, and does not become shelfware.

Sep 15, 20256 min read
Security

Broken Access Control Examples: Real Cases and How to Fix Them

Broken access control is the number-one web risk on the OWASP Top 10. These examples show what it looks like in real code and how to close each gap.

Sep 15, 20256 min read
Security

JavaScript Security Vulnerabilities: The Ones That Actually Bite

JavaScript security vulnerabilities cluster around a few patterns: XSS, prototype pollution, ReDoS, and dependency risk. Here is how each works and how to catch it.

Sep 15, 20256 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Security (Page 8) — Supply Chain Security Blog | Safeguard