Safeguard
Tag

appsec

Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.

596 articles

AppSec

Why We Use CORS in Node.js: Configuration Without the Foot-Guns

Understanding why we use CORS in Node.js starts with what it is not: CORS is a browser relaxation mechanism, not a security wall. Here is how to configure it in Express without the classic misconfigurations.

Apr 13, 20267 min read
AppSec

Secure Code Review: A Practical Checklist

Secure code reviews catch a different category of bug than functional code review, and having a repeatable checklist keeps reviewers from relying on memory for the same handful of recurring flaws.

Apr 13, 20265 min read
Security

iOS App Security Testing: A Practical Guide for Mobile Teams

iOS app security testing means checking storage, transport, and third-party code, not just trusting the App Store review. Here is how to do it well.

Apr 12, 20266 min read
Application Security

What is Threat Modeling

Threat modeling finds the design flaws scanners can't see. Learn what it is, when to do it, and how Safeguard ties it to reachability analysis.

Apr 12, 20266 min read
AppSec

SQL Injection Commands Explained: How the Attack Works and How to Stop It

Understanding the SQL injection commands attackers rely on is the fastest way to learn how to defend against them. This guide explains the classes conceptually and focuses on detection and remediation.

Apr 12, 20266 min read
Security

How to Run a Software Security Assessment

A software security assessment is a structured evaluation of an application's security posture across code, dependencies, configuration, and process. Here is how to run one that produces action, not a PDF.

Apr 12, 20266 min read
Security

Vulnerable Websites List: Legal Sites to Practice Security Testing

A curated vulnerable websites list of intentionally insecure apps and labs built for legal, hands-on security practice — plus the rules that keep your training from becoming a crime.

Apr 11, 20265 min read
Security

Vulnerability Checker: How to Scan Your Code and Websites for Flaws

What a vulnerability checker does, the different kinds (dependency, website, container), and how to choose and use one to actually reduce risk rather than generate noise.

Apr 11, 20266 min read
Application Security

Application Security Controls Explained

A breakdown of what application security controls actually are, which ones matter most for supply chain risk, and how to prioritize them without alert fatigue.

Apr 11, 20267 min read
Application Security

Application Security Maturity Models

OWASP SAMM, BSIMM, and NIST SSDF explained: what maturity levels really measure, which framework fits your org, and why federal attestation rules now force the question.

Apr 11, 20268 min read
Security

JavaScript Injection Attack: How It Works and How to Stop It

A JavaScript injection attack runs attacker-controlled script in a victim's browser or a Node.js process. Here is how the attack class works and the defenses that actually neutralize it.

Apr 11, 20266 min read
Application Security

Asset-First Application Security

Vulnerability-first scanning drowns teams in noise. Asset-first application security starts with a complete inventory, then layers reachability and context to cut backlogs by 90%.

Apr 11, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

appsec (Page 36) — Safeguard Blog