ci-cd-security
Safeguard articles tagged "ci-cd-security" — guides, analysis, and best practices for software supply chain and application security.
207 articles
Why EDR and proxy tools won't stop supply chain malware
EDR and network proxies were built to watch endpoints and traffic, not evaluate what a dependency does before it runs — here's why that gap keeps letting supply chain malware through.
Secrets detection: how it works and why it matters
How secrets detection tools catch leaked keys before attackers do, why breaches like Toyota's still happen, and how Safeguard compares to Aikido Security.
What is a Trusted Publisher (PyPI and npm)
A trusted publisher lets your CI workflow publish packages with short-lived OIDC tokens instead of stored API keys. Here's how it works on PyPI and where npm stands.
Application Security Scanning: How the Pieces Fit Together
Application security scanning spans SAST, DAST, SCA, and secrets detection. Here is what each type finds, where it fits in CI, and how to avoid alert fatigue.
PulseMeter report: software supply chain risk perceptions
Safeguard's latest PulseMeter survey finds 71% of teams hit a supply chain incident this year, but only 34% feel confident they'd catch one in time.
How to Mitigate Supply Chain Attacks: A Practical Playbook
To mitigate supply chain attacks, you secure everything you did not write: dependencies, build systems, and the pipeline that ships your code. Here is how.
Securing actions/setup-node in Your CI Pipeline
The actions/setup-node step looks harmless, but pinning, caching, and registry auth choices decide whether it becomes a supply chain foothold. Here is how to harden it.
SAST Scans Explained: How Static Analysis Finds Code Flaws
SAST scans read your source code without running it, tracing untrusted data from input to sink to catch injection and other flaws before they ship.
Cloud Application Security Best Practices
Five layers cover most of the risk in cloud apps: identity, secrets, artifact scanning, pipeline gates, and runtime guardrails. Here is how to build each one without slowing delivery.
Dockerfile Best Practices: Security, Size, and Build Speed
Most Dockerfiles are copy-pasted from a tutorial and never revisited. Here's what actually shrinks image size, closes the common security holes, and speeds up rebuilds.
Developer infrastructure posture: integrating ASPM early
Prisma Cloud built ASPM outward from the cloud. Real breaches like tj-actions and SolarWinds start earlier, in developer infrastructure that needs its own continuous posture model.
DevOps vs DevSecOps
DevOps ships code fast; DevSecOps ships it safely. Here's the concrete difference, backed by real breach data, costs, and pipeline mechanics.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.