appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
596 articles
Why We Use CORS in Node.js: Configuration Without the Foot-Guns
Understanding why we use CORS in Node.js starts with what it is not: CORS is a browser relaxation mechanism, not a security wall. Here is how to configure it in Express without the classic misconfigurations.
Secure Code Review: A Practical Checklist
Secure code reviews catch a different category of bug than functional code review, and having a repeatable checklist keeps reviewers from relying on memory for the same handful of recurring flaws.
iOS App Security Testing: A Practical Guide for Mobile Teams
iOS app security testing means checking storage, transport, and third-party code, not just trusting the App Store review. Here is how to do it well.
What is Threat Modeling
Threat modeling finds the design flaws scanners can't see. Learn what it is, when to do it, and how Safeguard ties it to reachability analysis.
SQL Injection Commands Explained: How the Attack Works and How to Stop It
Understanding the SQL injection commands attackers rely on is the fastest way to learn how to defend against them. This guide explains the classes conceptually and focuses on detection and remediation.
How to Run a Software Security Assessment
A software security assessment is a structured evaluation of an application's security posture across code, dependencies, configuration, and process. Here is how to run one that produces action, not a PDF.
Vulnerable Websites List: Legal Sites to Practice Security Testing
A curated vulnerable websites list of intentionally insecure apps and labs built for legal, hands-on security practice — plus the rules that keep your training from becoming a crime.
Vulnerability Checker: How to Scan Your Code and Websites for Flaws
What a vulnerability checker does, the different kinds (dependency, website, container), and how to choose and use one to actually reduce risk rather than generate noise.
Application Security Controls Explained
A breakdown of what application security controls actually are, which ones matter most for supply chain risk, and how to prioritize them without alert fatigue.
Application Security Maturity Models
OWASP SAMM, BSIMM, and NIST SSDF explained: what maturity levels really measure, which framework fits your org, and why federal attestation rules now force the question.
JavaScript Injection Attack: How It Works and How to Stop It
A JavaScript injection attack runs attacker-controlled script in a victim's browser or a Node.js process. Here is how the attack class works and the defenses that actually neutralize it.
Asset-First Application Security
Vulnerability-first scanning drowns teams in noise. Asset-first application security starts with a complete inventory, then layers reachability and context to cut backlogs by 90%.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.