appsec
Safeguard articles tagged "appsec" — guides, analysis, and best practices for software supply chain and application security.
591 articles
OWASP Top 10 Vulnerabilities 2023: A Retrospective That Still Applies
There was no new web OWASP Top 10 in 2023 — but the OWASP Top 10 vulnerabilities 2023 story is really about the 2021 web list holding firm and the API Security Top 10 getting a major refresh.
Shift-Left Security Explained: Catching Vulnerabilities Before Production
Shift-left security means moving vulnerability detection into design, coding, and CI instead of waiting for a pre-release pen test. Here is what that looks like in practice.
Web Vulnerability Scanning: How It Works and What It Finds
A practitioner's guide to web vulnerability scanning: what scanners actually test, where they fall short, and how to fit them into a delivery pipeline without drowning in noise.
API Scanner Tools: How They Work and How to Choose One
An API scanner tool probes your endpoints for authentication gaps, injection flaws, and data exposure before attackers do. Here is how the scanning works and what to look for when picking one.
Checkmarx Braga: How the Portugal R&D Hub Shapes Its AppSec Platform
Checkmarx Braga is one of the vendor's engineering centers, and it helps explain how the company builds its SAST and application security tooling. Here is what that means for teams evaluating the platform.
How a Code Error Solver Helps You Fix Bugs Without Adding Risk
A code error solver turns cryptic stack traces into fixes, but the tempting one-line patch it hands you can quietly introduce a vulnerability. Here is how to use one safely.
DevSecOps Threat Modeling: Baking Threat Analysis Into Your Pipeline
DevSecOps threat modeling moves risk analysis out of one-off workshops and into the delivery pipeline, so teams find design flaws before they ship.
eslint-plugin-security: How to Catch Node.js Security Bugs at Lint Time
eslint-plugin-security adds static-analysis rules to ESLint that flag risky Node.js patterns before they ship. Here is how to configure it and read its warnings without drowning in noise.
How to Use the express-validator npm Package Safely
A security-focused review of the express-validator npm package: what it protects you from, what it does not, and how to configure it so bad input never reaches your handlers.
Malicious Code Meaning: A Practical Definition for Developers
Malicious code is any software written to damage, disrupt, or gain unauthorized access to a system. Here is what the term actually covers and how it reaches your stack.
SAST Testing Tools: How to Choose and Use Them Effectively
A practitioner's guide to SAST testing tools: what static analysis actually catches, where it falls short, and how to wire it into a pipeline without drowning developers in noise.
A Practical SAST Tools List for Modern AppSec Teams
A working SAST tools list for teams that want static analysis in the pipeline, not just a scanner that files noise. What each tool is good at and how to choose.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.