appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
596 articles
react-query (TanStack Query): Package Health and Data-Fetching Safety
The npm react-query package froze at v3.39.3 when the project moved to @tanstack/react-query. Here is how to tell which one you are running, and how to keep server-state caching from leaking data.
DAST vs Pen Testing: Which One Does Your App Actually Need?
DAST is automated, continuous, and scales; penetration testing is manual, creative, and deep. Here is how they differ and why serious teams run both.
Free Web Security Scanner: How They Work and What to Use
A free web security scanner can find real vulnerabilities in a web app, but only if you understand what each type actually tests. Here is a practitioner's breakdown.
The Threat Modeling Process, Step by Step
Threat modeling answers four questions: what are we building, what can go wrong, what are we doing about it, and did we do enough? A concrete step-by-step process your team can run in an afternoon.
Stored XSS: Why Persistent Injection Hurts Most
Stored XSS saves the attacker's script server-side and serves it to everyone. Here is why persistent injection is the most damaging XSS variant and how to stop it.
SSRF Vulnerability Explained: How Server-Side Request Forgery Works and How to Stop It
An SSRF vulnerability lets an attacker make your server send requests on their behalf — the flaw behind the Capital One breach. Here's how it works and how to defend against it.
API Security Software: What It Does and How to Choose It
API security software protects the endpoints that carry most of your traffic and data. Here is what these tools actually do, the categories that matter, and how to choose without duplicating coverage.
Web Security Scan: How to Find Vulnerabilities Before Attackers Do
A web security scan probes your application for exploitable flaws the way an attacker would. Here is how the main scan types work and how to run them well.
SQL Injection Cheat Sheet: Detection and Defensive Patterns
A defensive SQLi cheat sheet that shows how injection works conceptually, how to spot it in code and traffic, and the parameterization patterns that actually stop it.
The Most Common Software Vulnerabilities and How to Prevent Them
The handful of common software vulnerabilities that keep showing up in real breaches, why they persist, and the concrete practices that shut each one down.
What Is a Vulnerability in Cyber Security? A Plain-English Guide
A vulnerability in cyber security is a weakness an attacker can exploit. Here is how vulnerabilities differ from threats and risks, and how teams find and fix them.
Static Code Scan: How SAST Finds Bugs Before They Ship
A static code scan analyzes source without running it, catching injection, secrets, and unsafe patterns early. Here is what it can and cannot see, and how to wire one into CI.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.