appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
596 articles
nimbus-jose-jwt: JWT Handling in Java Done Right
com.nimbusds:nimbus-jose-jwt is the JVM's workhorse JOSE library. Here is how to configure it so algorithm confusion, weak validation, and its one recent CVE never reach production.
GitGuardian vs TruffleHog: choosing a secrets detection tool in 2026
How GitGuardian and TruffleHog compare on detection accuracy, false positive handling, remediation workflow, and enterprise rollout for secrets scanning programs.
jwt-decode: Why Decoding Is Not Verifying (Security Guide)
The npm jwt-decode package reads JWT claims without checking the signature. That is by design, and it is behind a whole class of authentication bypasses when developers forget it.
Tool Consolidation ROI Rubric for AppSec in 2026
A rubric for calculating the real ROI of AppSec tool consolidation in 2026, with the cost categories that get missed and the patterns that genuinely save money.
Enterprise Security Tools: What Actually Belongs in Your Stack
Enterprise security tools span identity, endpoint, network, application, and data layers. Here is a practical map of what each category does and how to avoid buying overlap.
How a Web Application Penetration Test Actually Works (and What It Finds)
A web application penetration test simulates a real attacker against your app. Here is what the phases look like and how to act on the report.
DAST Testing: How Dynamic Scans Probe Running Applications
DAST testing attacks your app the way an outsider would — no source code, just HTTP requests against a running target. Here is how the scan works, what it catches that SAST misses, and where it falls short.
What Is a White Box Penetration Test?
A clear explanation of the white box penetration test: how full-knowledge testing differs from black and gray box, what testers get, and when it is the right choice.
What a Website Security Checker Really Checks
A website security checker scans a site for exposed vulnerabilities, misconfigurations, and known-bad dependencies. Here is what it catches and where it stops.
DAST Scanning Tools: What They Are and How to Choose One
DAST scanning tools test a running application from the outside to find runtime flaws. Here is how they work, what they catch, and how to pick one.
SCA Full Form in Engineering: What Software Composition Analysis Means
In software engineering and security, the SCA full form is Software Composition Analysis: the practice of inventorying and vetting the open-source components your code depends on.
sanitize-html Vulnerabilities: History and Correct Configuration
A walk through the real npm sanitize-html vulnerabilities, from the 2016 recursion bypass to the 2024 style-attribute leak, and the configuration that keeps the library safe.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.