Safeguard
Tag

appsec

Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.

596 articles

Security

Enterprise Level Security: A Practical Guide

Enterprise level security is less about buying premium tools and more about controls that hold up under scale, audit, and adversaries. Here is what actually distinguishes it.

Jun 22, 20266 min read
Security

Serialisation in Java: A Security Guide

How Java serialisation works, why deserialising untrusted data is dangerous, and the filters and patterns that keep it from becoming remote code execution.

Jun 22, 20266 min read
Security

ngx-cookie-service: Secure Cookie Handling in Angular

ngx-cookie-service makes reading and writing cookies in Angular trivial, but the security depends entirely on the flags you set. Here is how to use it without leaking session data.

Jun 22, 20266 min read
AI Security

What is AI Code Remediation?

AI code remediation turns vulnerability findings into ready-to-merge patches. Here's how it works, where Veracode's approach falls short, and how Safeguard closes the gap.

Jun 21, 20267 min read
AppSec

Code Scan Tools: How They Work and What to Use

A practical breakdown of code scan tool categories — SAST, SCA, secrets, and DAST — how each works, and how to choose and combine them without alert fatigue.

Jun 20, 20266 min read
Application Security

OWASP Testing Tools and Methodology

OWASP testing tools cover the methodology; Veracode wraps part of it commercially. Neither was built for supply chain risk — here's where the gaps are and how to close them.

Jun 20, 20267 min read
AppSec

Source Code Analysis Tools: SAST, Linters, and Semantic Engines

Not all source code analysis tools do the same job. Linters, pattern-based SAST, and semantic dataflow engines catch different bug classes, and mixing them up wastes budget.

Jun 19, 20266 min read
Security

Security Testing Tools for Mobile Applications: What Actually Finds Bugs

A practitioner's guide to the security testing tools for mobile applications that matter — SAST, DAST, dependency scanning, and runtime instrumentation — and how to combine them without drowning in noise.

Jun 19, 20267 min read
Security

How to Write an Application Security Policy Teams Actually Follow

An application security policy only works if engineers can act on it. Here's how to write one that sets clear requirements, maps to real controls, and does not become shelfware.

Jun 18, 20266 min read
Security

Broken Access Control Examples: Real Cases and How to Fix Them

Broken access control is the number-one web risk on the OWASP Top 10. These examples show what it looks like in real code and how to close each gap.

Jun 18, 20266 min read
Security

Snyk in Cybersecurity: Where It Fits in a Modern AppSec Program

How Snyk fits into a cybersecurity program: what its developer-first SCA, SAST, container, and IaC tools cover, and what they leave for other controls.

Jun 18, 20265 min read
Compliance

FedRAMP Moderate authorization and AppSec controls

Veracode's FedRAMP Moderate authorization is a procurement accelerant, not proof of AppSec efficacy. Here's what the badge covers, what it doesn't, and what federal buyers should verify.

Jun 18, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

appsec (Page 15) — Safeguard Blog