appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
591 articles
White Box Pen Testing: How It Works and When to Use It
White box pen testing gives the tester full access to source, architecture, and credentials. Here's how it differs from black box, when to choose it, and the tools involved.
Open Source SAST Tools Worth Evaluating
A rundown of the open source SAST tools engineering teams actually use in production, and where each one runs out of road.
Code Injection in Python: How It Happens and How to Prevent It
Code injection python vulnerabilities almost always trace back to eval, exec, or a template engine handed untrusted input; here is how the attack works and how to close it off.
Website Vulnerability Scanners: How They Work and What They Miss
How a website vulnerability scanner crawls, fuzzes, and fingerprints your app, plus the whole classes of flaws it structurally cannot find on its own.
SAST Testing: How Static Analysis Finds Bugs Before They Run
A SAST test analyzes source code without executing it to find vulnerabilities like injection and hardcoded secrets. Here is how it works and where it fits.
Local Storage Security: What to Store and What Never To
Local storage security comes down to one rule most apps break: the browser's localStorage is readable by any JavaScript on the page, so it is no place for secrets.
Gray Box Testing Explained: A Security Guide
Gray box testing gives a tester partial internal knowledge, splitting the difference between black box and white box. Here is when it finds bugs the other two miss.
Statische Code-Analyse: Sicherheitsluecken finden, bevor Code laeuft
Statische Code-Analyse prueft Quellcode ohne ihn auszufuehren und findet Sicherheitsluecken frueh. So funktioniert sie und welche Tools sich lohnen.
Web Application Penetration Testing: What to Expect
A real web application penetration test follows a scoped, multi-phase process — here's what happens before, during, and after the engagement so the report doesn't surprise you.
IAST Meaning: What Interactive Application Security Testing Does
IAST instruments a running application from the inside, watching real execution to confirm vulnerabilities with far fewer false positives than static scanning.
Enso Security and ASPM: What It Is and Why It Matters
Enso Security pioneered Application Security Posture Management before its 2023 acquisition by Snyk. Here is what ASPM solves and how the category has evolved.
White Box Pentesting: A Practical Guide to Full-Knowledge Testing
White box pentesting gives the tester source code, architecture, and credentials up front. Here is when that full-knowledge approach beats black box, and how an engagement actually runs.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.