Safeguard
Tag

appsec

Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.

591 articles

AppSec

OWASP Top 10 Vulnerabilities 2023: A Retrospective That Still Applies

There was no new web OWASP Top 10 in 2023 — but the OWASP Top 10 vulnerabilities 2023 story is really about the 2021 web list holding firm and the API Security Top 10 getting a major refresh.

Mar 18, 20258 min read
Security

Shift-Left Security Explained: Catching Vulnerabilities Before Production

Shift-left security means moving vulnerability detection into design, coding, and CI instead of waiting for a pre-release pen test. Here is what that looks like in practice.

Mar 18, 20257 min read
AppSec

Web Vulnerability Scanning: How It Works and What It Finds

A practitioner's guide to web vulnerability scanning: what scanners actually test, where they fall short, and how to fit them into a delivery pipeline without drowning in noise.

Mar 18, 20256 min read
AppSec

API Scanner Tools: How They Work and How to Choose One

An API scanner tool probes your endpoints for authentication gaps, injection flaws, and data exposure before attackers do. Here is how the scanning works and what to look for when picking one.

Mar 18, 20256 min read
Security

Checkmarx Braga: How the Portugal R&D Hub Shapes Its AppSec Platform

Checkmarx Braga is one of the vendor's engineering centers, and it helps explain how the company builds its SAST and application security tooling. Here is what that means for teams evaluating the platform.

Mar 18, 20256 min read
Security

How a Code Error Solver Helps You Fix Bugs Without Adding Risk

A code error solver turns cryptic stack traces into fixes, but the tempting one-line patch it hands you can quietly introduce a vulnerability. Here is how to use one safely.

Mar 18, 20256 min read
Security

DevSecOps Threat Modeling: Baking Threat Analysis Into Your Pipeline

DevSecOps threat modeling moves risk analysis out of one-off workshops and into the delivery pipeline, so teams find design flaws before they ship.

Mar 18, 20256 min read
Security

eslint-plugin-security: How to Catch Node.js Security Bugs at Lint Time

eslint-plugin-security adds static-analysis rules to ESLint that flag risky Node.js patterns before they ship. Here is how to configure it and read its warnings without drowning in noise.

Mar 18, 20255 min read
Open Source

How to Use the express-validator npm Package Safely

A security-focused review of the express-validator npm package: what it protects you from, what it does not, and how to configure it so bad input never reaches your handlers.

Mar 18, 20256 min read
Security

Malicious Code Meaning: A Practical Definition for Developers

Malicious code is any software written to damage, disrupt, or gain unauthorized access to a system. Here is what the term actually covers and how it reaches your stack.

Mar 18, 20256 min read
AppSec

SAST Testing Tools: How to Choose and Use Them Effectively

A practitioner's guide to SAST testing tools: what static analysis actually catches, where it falls short, and how to wire it into a pipeline without drowning developers in noise.

Mar 18, 20257 min read
AppSec

A Practical SAST Tools List for Modern AppSec Teams

A working SAST tools list for teams that want static analysis in the pipeline, not just a scanner that files noise. What each tool is good at and how to choose.

Mar 18, 20255 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

appsec (Page 42) — Safeguard Blog