appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
596 articles
How an API Security Scanner Works and What to Use
An API security scanner automatically probes your endpoints for authentication, authorization, and injection flaws. Here is how they work and how to fit one into your pipeline.
SOC 2 Type II reporting for AppSec vendors and buyers
A SOC 2 Type II badge isn't enough due diligence for AppSec vendors. Here's what to actually check in the report—scope, exceptions, and subservice carve-outs—before you trust one.
How Snyk Code's security rule sets are structured and ver...
A technical look at how Snyk Code structures, scores, and versions its SAST rules — from the DeepCode AI engine to CWE mapping and custom rule bundles.
Why a Customer Trust Center matters for vendor risk reviews
Vendor security reviews stall without a live trust center. See what appsec teams check, how Veracode approaches transparency, and how Safeguard's trust center speeds reviews.
JavaScript Hacking Explained: Attack Classes and Defenses
JavaScript hacking is less about breaking the language and more about abusing how apps handle untrusted input. Here are the main attack classes and how to defend against each.
SQL Injection Strategies: A Free Guide (No PDF Download Needed)
Looking for a SQL injection strategies PDF free download? Here is the defensive material that actually matters, covering how the attack works and how to shut it down.
App Vulnerability Scanner: How It Works and What to Use
An app vulnerability scanner automatically probes your application for known flaws and misconfigurations. Here is how the main types work and how to pick the right one.
Building Securely with AI (secure AI-assisted development)
AI coding assistants ship code fast — Veracode found 45% of AI-generated code contains security flaws. Here's what secure AI-assisted development actually requires.
How Snyk Agent Fix's agentic retry loop self-corrects fai...
A technical look at how Snyk's Agent Fix uses a bounded, feedback-driven retry loop to validate and self-correct AI-generated vulnerability fixes before they reach a pull request.
SSRF Meaning: What Server-Side Request Forgery Is and How to Stop It
SSRF stands for Server-Side Request Forgery, a vulnerability where an attacker tricks your server into making requests on their behalf. Here is what it means, why it is dangerous, and how to defend against it.
Black Duck and Synopsys: What the Spinoff Means for SCA
Black Duck is now an independent company after splitting from Synopsys in 2024. Here is what changed, and what it means if you rely on it for SCA.
Checkmarx DAST: What It Does and How It Fits an AppSec Program
Checkmarx DAST is the dynamic testing component of the Checkmarx One platform, scanning running web apps and APIs for vulnerabilities. Here is how it works and where it fits.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.