Safeguard
Tag

appsec

Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.

591 articles

AppSec

White Box Pen Testing: How It Works and When to Use It

White box pen testing gives the tester full access to source, architecture, and credentials. Here's how it differs from black box, when to choose it, and the tools involved.

May 14, 20256 min read
AppSec

Open Source SAST Tools Worth Evaluating

A rundown of the open source SAST tools engineering teams actually use in production, and where each one runs out of road.

May 14, 20255 min read
AppSec

Code Injection in Python: How It Happens and How to Prevent It

Code injection python vulnerabilities almost always trace back to eval, exec, or a template engine handed untrusted input; here is how the attack works and how to close it off.

May 14, 20256 min read
AppSec

Website Vulnerability Scanners: How They Work and What They Miss

How a website vulnerability scanner crawls, fuzzes, and fingerprints your app, plus the whole classes of flaws it structurally cannot find on its own.

May 13, 20256 min read
AppSec

SAST Testing: How Static Analysis Finds Bugs Before They Run

A SAST test analyzes source code without executing it to find vulnerabilities like injection and hardcoded secrets. Here is how it works and where it fits.

May 12, 20256 min read
Security

Local Storage Security: What to Store and What Never To

Local storage security comes down to one rule most apps break: the browser's localStorage is readable by any JavaScript on the page, so it is no place for secrets.

May 9, 20255 min read
Security

Gray Box Testing Explained: A Security Guide

Gray box testing gives a tester partial internal knowledge, splitting the difference between black box and white box. Here is when it finds bugs the other two miss.

May 9, 20256 min read
Security

Statische Code-Analyse: Sicherheitsluecken finden, bevor Code laeuft

Statische Code-Analyse prueft Quellcode ohne ihn auszufuehren und findet Sicherheitsluecken frueh. So funktioniert sie und welche Tools sich lohnen.

May 9, 20255 min read
AppSec

Web Application Penetration Testing: What to Expect

A real web application penetration test follows a scoped, multi-phase process — here's what happens before, during, and after the engagement so the report doesn't surprise you.

May 9, 20255 min read
AppSec

IAST Meaning: What Interactive Application Security Testing Does

IAST instruments a running application from the inside, watching real execution to confirm vulnerabilities with far fewer false positives than static scanning.

May 8, 20256 min read
Security

Enso Security and ASPM: What It Is and Why It Matters

Enso Security pioneered Application Security Posture Management before its 2023 acquisition by Snyk. Here is what ASPM solves and how the category has evolved.

May 6, 20255 min read
AppSec

White Box Pentesting: A Practical Guide to Full-Knowledge Testing

White box pentesting gives the tester source code, architecture, and credentials up front. Here is when that full-knowledge approach beats black box, and how an engagement actually runs.

May 6, 20256 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

appsec (Page 37) — Safeguard Blog