Safeguard
Tag

appsec

Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.

596 articles

Open Source

The cors npm Package: A Security Review and Safe Usage Guide

The cors npm package is the standard CORS middleware for Express, and most of its danger comes from misconfiguration, not the library itself. Here is how to set it correctly.

May 7, 20265 min read
Security

Security By Default: A Practical Guide

Security by default means the safe path is the default path, and the insecure option takes deliberate effort to reach. Here is how to design systems that protect users before anyone configures anything.

May 6, 20266 min read
AppSec

The OWASP Logo and Brand: What It Means and How to Use It Correctly

The OWASP logo is a registered mark of a nonprofit, not a free-for-all badge. Here is what the wasp actually stands for and the rules for putting it on your site or slides.

May 6, 20266 min read
Application Security

Taint Analysis vs Reachability: What You Actually Need in 2026

Taint and reachability sound similar and answer different questions. Here is when each one matters, where vendors blur the line, and how to use both.

May 6, 20266 min read
AI Security

AI Cybersecurity Tools and Solutions: The 2026 Landscape

AI cybersecurity tools in 2026 split into three real categories — AI-augmented detection, AI-specific application security, and autonomous response — and most vendors only actually cover one.

May 6, 20265 min read
AppSec

Gartner DAST: How Analysts Frame Dynamic Application Security Testing

Gartner does not publish a standalone DAST ranking; it covers dynamic testing inside its broader application security testing research. Here is how analysts categorize DAST and what to take from it.

May 6, 20266 min read
Application Security

SonarQube SCA Capability Review 2026

A working review of SonarQube's SCA capability in 2026, comparing it against dedicated SCA tools on coverage, reachability, policy depth, and developer experience.

May 6, 20265 min read
Containers

PHP Docker: How to Build a Secure PHP Docker Image

A secure PHP Docker setup starts with a supported base tag, a slim image, a non-root user, and a scanned dependency tree. Here is how to get all four.

May 6, 20265 min read
Security

Vulnerability Assessment as a Service: What It Is and When You Need It

How vulnerability assessment as a service works, what it covers, and how to tell whether a managed scanning service fits your team better than in-house tooling.

May 6, 20266 min read
AppSec

SQL Injection for Beginners: How It Works and How to Stop It

SQL injection for beginners, explained without the hype: what the attack actually is, why string-built queries cause it, and the one habit — parameterized queries — that closes the door.

May 6, 20266 min read
AppSec

What Is a CSRF Attack? Detection and Prevention Guide

A CSRF attack tricks a logged-in user's browser into sending forged requests. Here is how the attack works and how to shut it down with modern defenses.

May 5, 20267 min read
Security

Nuxt Security: Hardening Your Nuxt App Against Real Threats

A practical Nuxt security guide covering the nuxt-security module, Content Security Policy with SSR nonces, server-route risks, and dependency hygiene.

May 5, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

appsec (Page 28) — Safeguard Blog