dependencies
Safeguard articles tagged "dependencies" — guides, analysis, and best practices for software supply chain and application security.
74 articles
react-slick: Security and Maintenance Guide for 2025
react-slick is a hugely popular carousel component with no known CVEs, but slowing maintenance and its dependency chain are the risks worth watching before you adopt it.
Is python-docx Safe? A Security Guide
python-docx reads and writes Word documents in Python. Here is what its security posture actually depends on, especially when you open files you did not create.
The moment npm Package in 2025: Security Review and Safe Usage
The moment npm package is in maintenance mode, not abandoned. Here is what that means for security, when it is fine to keep, and what to migrate to when it is not.
npm classnames: Security Review and Safe Usage
The npm classnames package is a tiny, widely used utility for conditionally joining CSS class names. Here is its security profile and how to use it safely in React.
prism-react-renderer: Safe Syntax Highlighting in React
prism-react-renderer gives you tokenized syntax highlighting in React without dangerouslySetInnerHTML. Here is how it works, why that matters for XSS, and how to keep the dependency healthy.
Software Supply Chain Vulnerability Protection: How to Secure Your Dependencies
Software supply chain vulnerability protection means finding and fixing risk in the code you didn't write. Here is how detection, prioritization, and policy fit together.
What Is a Dependency in Programming?
A dependency is any external code your software relies on to run. Here is what that really means, how direct and transitive dependencies differ, and why the concept sits at the heart of software supply chain security.
npm react-scripts: A Security Review and Safe Usage Guide
react-scripts powers Create React App, but CRA is now deprecated and react-scripts carries a stack of aging transitive dependencies. Here is how to handle it safely.
When Is SCA Required? A Software Composition Analysis Guide
SCA is required wherever you ship code built on open-source dependencies and need to prove which components you use and whether they carry known vulnerabilities.
ng-bootstrap: Using and Securing Angular's Bootstrap Widgets
ng-bootstrap gives Angular apps native Bootstrap widgets with no jQuery dependency. Here is how to keep it current and where the real security work actually lives.
How to Avoid Malicious Code: A Practical Defense Checklist
How to avoid malicious code in practice: control what you install, control what runs at install time, and control what your build can reach. A working checklist for teams.
Fix My Java Code: A Practical Guide to Finding and Fixing Security Bugs
"Fix my Java code" usually means a security or dependency problem. Here is a repeatable way to find the real fault, fix it, and stop it from returning.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.