database
Safeguard articles tagged "database" — guides, analysis, and best practices for software supply chain and application security.
6 articles
The Permission You Just Revoked, According to a Replica That Has Not Heard Yet
A user is removed from a project. The write succeeds on the primary immediately. For the next several hundred milliseconds, a read replica still shows them as a member, and if any authorization check reads from it, they can still act.
Your Application Connects as a User That Can Do Everything
A SQL injection is limited by what the connected user may do, and so is a compromised application process. In most deployments the answer is everything, because that is what the framework quickstart produced.
The Migration Is the Riskiest Part of the Pull Request
It runs in production with the highest privileges in your system, usually unattended, and gets reviewed as an implementation detail at the bottom of the diff. It can drop a constraint that was the only thing enforcing a security property.
Database Credential Security (2026 Guide)
Database credentials are the last door between an attacker and your data. This guide covers eliminating static passwords with IAM auth, scoping least privilege, rotating safely, and detecting leaked connection strings.
SQL Injection in Go: Why database/sql Is Safe Until You Reach for Sprintf
database/sql gives Go parameterized queries for free — yet SQL injection still ships in Go services through dynamic query building, ORM escape hatches, and misused identifiers. Here's the line you can't cross.
CVE-2025-1094 in PostgreSQL psql: Patch Posture & SBOM Response
PostgreSQL psql SQL injection scored CVSS 8.1 and patched in 17.3 / 16.7 / 15.11 / 14.16 / 13.19. Defender SBOM and rollout playbook.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.