appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
591 articles
Artificial Intelligence Security Tools: What They Do and How to Choose
Artificial intelligence security tools now sit in two camps: tools that use AI to defend software, and tools that defend the AI itself. Knowing which one you need shapes the whole buying decision.
DevSecOps SAST: How to Wire Static Analysis Into Your Pipeline
SAST in DevSecOps means catching code-level flaws before they merge, not after they ship. Here is how to integrate static analysis so developers actually use it.
The Java Cheat Sheet Developers Actually Need for Secure Code
Most Java cheat sheets stop at syntax. This one is the security-focused reference: the APIs, patterns, and one-liners that keep injection, deserialization, and crypto bugs out of your code.
Web Session Security: A Practical Guide
Web session security is the set of controls that keep a logged-in user's session token from being stolen, guessed, or reused by an attacker — and most of it comes down to a handful of cookie flags and lifecycle rules teams routinely skip.
AppSec Program Management: Building One That Sticks
AppSec program management is the discipline of turning scattered security tools into a governed, measurable program with owners, policies, and metrics. Here is how to build one.
Vulnerability Assessment Services: What's Actually Included
Vulnerability assessment services bundle scanning, triage, and remediation tracking — but the scope varies widely between vendors, and knowing what's actually included changes what you should pay.
VAPT Meaning: What Vulnerability Assessment and Penetration Testing Actually Covers
VAPT stands for Vulnerability Assessment and Penetration Testing — two different security exercises that get bundled into one acronym. Here is what each half does and when you need which.
The cors npm Package: A Security Review and Safe Usage Guide
The cors npm package is the standard CORS middleware for Express, and most of its danger comes from misconfiguration, not the library itself. Here is how to set it correctly.
Security By Default: A Practical Guide
Security by default means the safe path is the default path, and the insecure option takes deliberate effort to reach. Here is how to design systems that protect users before anyone configures anything.
The OWASP Logo and Brand: What It Means and How to Use It Correctly
The OWASP logo is a registered mark of a nonprofit, not a free-for-all badge. Here is what the wasp actually stands for and the rules for putting it on your site or slides.
Gartner DAST: How Analysts Frame Dynamic Application Security Testing
Gartner does not publish a standalone DAST ranking; it covers dynamic testing inside its broader application security testing research. Here is how analysts categorize DAST and what to take from it.
PHP Docker: How to Build a Secure PHP Docker Image
A secure PHP Docker setup starts with a supported base tag, a slim image, a non-root user, and a scanned dependency tree. Here is how to get all four.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.