appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
596 articles
The cors npm Package: A Security Review and Safe Usage Guide
The cors npm package is the standard CORS middleware for Express, and most of its danger comes from misconfiguration, not the library itself. Here is how to set it correctly.
Security By Default: A Practical Guide
Security by default means the safe path is the default path, and the insecure option takes deliberate effort to reach. Here is how to design systems that protect users before anyone configures anything.
The OWASP Logo and Brand: What It Means and How to Use It Correctly
The OWASP logo is a registered mark of a nonprofit, not a free-for-all badge. Here is what the wasp actually stands for and the rules for putting it on your site or slides.
Taint Analysis vs Reachability: What You Actually Need in 2026
Taint and reachability sound similar and answer different questions. Here is when each one matters, where vendors blur the line, and how to use both.
AI Cybersecurity Tools and Solutions: The 2026 Landscape
AI cybersecurity tools in 2026 split into three real categories — AI-augmented detection, AI-specific application security, and autonomous response — and most vendors only actually cover one.
Gartner DAST: How Analysts Frame Dynamic Application Security Testing
Gartner does not publish a standalone DAST ranking; it covers dynamic testing inside its broader application security testing research. Here is how analysts categorize DAST and what to take from it.
SonarQube SCA Capability Review 2026
A working review of SonarQube's SCA capability in 2026, comparing it against dedicated SCA tools on coverage, reachability, policy depth, and developer experience.
PHP Docker: How to Build a Secure PHP Docker Image
A secure PHP Docker setup starts with a supported base tag, a slim image, a non-root user, and a scanned dependency tree. Here is how to get all four.
Vulnerability Assessment as a Service: What It Is and When You Need It
How vulnerability assessment as a service works, what it covers, and how to tell whether a managed scanning service fits your team better than in-house tooling.
SQL Injection for Beginners: How It Works and How to Stop It
SQL injection for beginners, explained without the hype: what the attack actually is, why string-built queries cause it, and the one habit — parameterized queries — that closes the door.
What Is a CSRF Attack? Detection and Prevention Guide
A CSRF attack tricks a logged-in user's browser into sending forged requests. Here is how the attack works and how to shut it down with modern defenses.
Nuxt Security: Hardening Your Nuxt App Against Real Threats
A practical Nuxt security guide covering the nuxt-security module, Content Security Policy with SSR nonces, server-route risks, and dependency hygiene.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.