Safeguard
Tag

appsec

Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.

596 articles

Concepts

What Is Threat Modeling?

Threat modeling is the structured practice of asking what can go wrong with a system before you build it, then designing controls to match. Here's the four-question framework, how to run a session, and where it fits supply chain security.

Jul 1, 20267 min read
Application Security

How GitHub used secret scanning to reach 'inbox zero' on ...

GitHub spent nine months clearing 20,000+ secret scanning alerts across 15,000 repos, finding 90% were noise. Here's how they beat alert fatigue, and how Safeguard automates it.

Jul 1, 20267 min read
AppSec

Mobile Application Penetration Testing: A Practical Guide

How mobile application penetration testing actually works — the methodology, the tools, and what to expect from a good engagement — from someone who runs them.

Jun 29, 20266 min read
AppSec

XSS Payloads on GitHub: What Those Repos Contain and How to Defend

Searching for XSS payloads on GitHub turns up huge lists of test strings. Here is what they are actually for, how defenders use them responsibly, and how to stop cross-site scripting in your own code.

Jun 28, 20267 min read
AppSec

DAST Tools List: The Dynamic Application Security Scanners That Matter

A practical DAST tools list for 2025: the open source and commercial scanners worth knowing, what each is good at, and how to fit DAST into your pipeline.

Jun 28, 20265 min read
AppSec

An XSS Example That Explains How Cross-Site Scripting Works

A clear XSS example shows how unescaped user input becomes executable script in a victim's browser, and why output encoding and CSP are the fixes that hold.

Jun 28, 20267 min read
AppSec

DAST Automated Testing: How It Works and Why It Belongs in CI

A DAST automated test probes your running application for vulnerabilities the way an attacker would, on every build. Here is how it works and the benefits of wiring it into CI.

Jun 28, 20266 min read
Buyer's Guides

Unified AppSec platform vs. stitched-together point solut...

Checkmarx built its AppSec suite through years of acquisitions. Safeguard built one risk graph. Here's how to verify which model actually reduces triage work.

Jun 27, 20268 min read
Buyer's Guides

Checkmarx vs Veracode: platform comparison

Checkmarx and Veracode both scan code for vulnerabilities. Here is how the platforms compare, and where software supply chain security fits in.

Jun 27, 20267 min read
Buyer's Guides

Checkmarx alternatives for enterprise AppSec teams

Checkmarx bundles SAST, SCA, and DAST into one platform. For teams whose real gap is supply chain risk, here's how Safeguard compares on reachability, SBOM, and deployment.

Jun 27, 20268 min read
AppSec

SQL Injection Detected: What the Alert Means and How to Respond

A SQL injection detected alert means a scanner or WAF found input reaching your database as executable code. Here is how to confirm it, triage it, and fix the root cause.

Jun 26, 20267 min read
Security

Threat Model Examples: Walkthroughs You Can Actually Copy

Concrete threat model examples for a web app, an API, and a CI/CD pipeline, using STRIDE and data flow diagrams to show how the process works end to end.

Jun 26, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

appsec (Page 13) — Safeguard Blog