appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
596 articles
Enterprise Level Security: A Practical Guide
Enterprise level security is less about buying premium tools and more about controls that hold up under scale, audit, and adversaries. Here is what actually distinguishes it.
Serialisation in Java: A Security Guide
How Java serialisation works, why deserialising untrusted data is dangerous, and the filters and patterns that keep it from becoming remote code execution.
ngx-cookie-service: Secure Cookie Handling in Angular
ngx-cookie-service makes reading and writing cookies in Angular trivial, but the security depends entirely on the flags you set. Here is how to use it without leaking session data.
What is AI Code Remediation?
AI code remediation turns vulnerability findings into ready-to-merge patches. Here's how it works, where Veracode's approach falls short, and how Safeguard closes the gap.
Code Scan Tools: How They Work and What to Use
A practical breakdown of code scan tool categories — SAST, SCA, secrets, and DAST — how each works, and how to choose and combine them without alert fatigue.
OWASP Testing Tools and Methodology
OWASP testing tools cover the methodology; Veracode wraps part of it commercially. Neither was built for supply chain risk — here's where the gaps are and how to close them.
Source Code Analysis Tools: SAST, Linters, and Semantic Engines
Not all source code analysis tools do the same job. Linters, pattern-based SAST, and semantic dataflow engines catch different bug classes, and mixing them up wastes budget.
Security Testing Tools for Mobile Applications: What Actually Finds Bugs
A practitioner's guide to the security testing tools for mobile applications that matter — SAST, DAST, dependency scanning, and runtime instrumentation — and how to combine them without drowning in noise.
How to Write an Application Security Policy Teams Actually Follow
An application security policy only works if engineers can act on it. Here's how to write one that sets clear requirements, maps to real controls, and does not become shelfware.
Broken Access Control Examples: Real Cases and How to Fix Them
Broken access control is the number-one web risk on the OWASP Top 10. These examples show what it looks like in real code and how to close each gap.
Snyk in Cybersecurity: Where It Fits in a Modern AppSec Program
How Snyk fits into a cybersecurity program: what its developer-first SCA, SAST, container, and IaC tools cover, and what they leave for other controls.
FedRAMP Moderate authorization and AppSec controls
Veracode's FedRAMP Moderate authorization is a procurement accelerant, not proof of AppSec efficacy. Here's what the badge covers, what it doesn't, and what federal buyers should verify.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.