Safeguard
Topic

Security

In-depth guides and analysis on security from the Safeguard engineering team.

521 articles

Security

A DevSecOps Checklist That Actually Works in Production

A practical DevSecOps checklist organized by pipeline stage, from pre-commit to runtime, with the controls that matter and the ones that just generate noise.

Sep 15, 20257 min read
Security

Snyk in Cybersecurity: Where It Fits in a Modern AppSec Program

How Snyk fits into a cybersecurity program: what its developer-first SCA, SAST, container, and IaC tools cover, and what they leave for other controls.

Sep 14, 20255 min read
Security

spring-security-core: A Practical Security Guide

The spring-security-core artifact is the foundation of Spring Security, providing authentication and authorization primitives. Here is how to use it safely.

Sep 12, 20255 min read
Security

JavaScript Hacking Explained: Attack Classes and Defenses

JavaScript hacking is less about breaking the language and more about abusing how apps handle untrusted input. Here are the main attack classes and how to defend against each.

Sep 11, 20256 min read
Security

Open Source Licence Compliance: A Security and Legal Guide

An open source licence is not just a legal footnote — it dictates what you can ship, and getting the obligations wrong creates real risk. Here is how to read them.

Sep 11, 20257 min read
Security

JavaScript Exploits Explained: How They Work and How to Stop Them

JavaScript exploits target the code that runs in browsers and on Node servers. Here is how the main attack classes work and the defenses that actually hold up.

Sep 11, 20255 min read
Security

Snyk Status: How to Check if Snyk Is Down and What to Do About It

The Snyk status page at status.snyk.io tells you whether the platform, its scanners, and integrations are healthy. Here is how to read it and how to keep a Snyk outage from breaking your pipeline.

Sep 11, 20256 min read
Security

AWS Application Security: A Practical Guide to Locking Down Your Workloads

AWS application security is a shared responsibility, and most incidents come from the customer side of that line. Here is a practical guide to the controls that actually prevent them.

Sep 11, 20256 min read
Security

Malware Meaning: What It Is and How It Spreads

The meaning of malware is simple — any software written to harm, exploit, or gain unauthorized access — but the categories and delivery methods are worth knowing.

Sep 10, 20255 min read
Security

nginx 1.22.1 Vulnerabilities: What Actually Affects You

Worried about nginx 1.22.1 vulnerabilities? Here is what genuinely affects this release, what does not, and how to decide whether you need to upgrade.

Sep 9, 20255 min read
Security

Black Duck and Synopsys: What the Spinoff Means for SCA

Black Duck is now an independent company after splitting from Synopsys in 2024. Here is what changed, and what it means if you rely on it for SCA.

Sep 9, 20255 min read
Security

Blind and Out-of-Band XXE: How XXE Injection Really Works

A defensive guide to XXE injection, including the blind and out-of-band variants that leak data with no visible response, plus how to detect and shut them down.

Sep 9, 20256 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Security (Page 9) — Supply Chain Security Blog | Safeguard