Safeguard
Tag

dependency-management

Safeguard articles tagged "dependency-management" — guides, analysis, and best practices for software supply chain and application security.

197 articles

Open Source

How to Check for npm Vulnerabilities (and Actually Fix Them)

npm check vulnerabilities the right way: what npm audit tells you, where it misleads, and how to turn a wall of advisories into a short list of things worth fixing.

May 12, 20265 min read
Open Source

react-native-inappbrowser-reborn: A Security Review of the In-App Browser Package

A practitioner's security look at react-native-inappbrowser-reborn: what it does, where the risk lives, and how to vet it and siblings like react-native-wifi-reborn.

May 11, 20266 min read
DevSecOps

netty-codec-http2 in Maven: Vulnerabilities and Fixes

The netty-codec-http2 Maven artifact powers HTTP/2 in gRPC, Spring, and countless services. Here are the CVEs that matter, the safe versions, and how to find it in your tree.

May 11, 20266 min read
Buyer's Guides

Socket.dev vs Dependabot: beyond automated dependency upd...

Dependabot patches known CVEs; Socket.dev flags risky package behavior. Neither enforces policy or ties risk to your actual build and runtime footprint — here's where Safeguard fits.

May 11, 20267 min read
Security

What Makes a Good Open Source Security Platform?

An open source security platform has to cover the whole dependency lifecycle, not just print CVEs. Here is what the category actually includes and how to evaluate one for your stack.

May 10, 20266 min read
DevSecOps

Runbooks for Dependency Disclosure Events

Detailed runbooks for responding to dependency CVE disclosures across languages and ecosystems, with roles, commands, and timelines tuned for automation.

May 10, 20266 min read
Security

PHP Security Issues: The Vulnerabilities That Still Bite in 2025

Most PHP security issues come down to a handful of repeatable mistakes: unsanitized input, weak session handling, and outdated dependencies. Here is what breaks and how to fix it.

May 9, 20265 min read
Open Source

Rimraf npm: Is It Still Worth Installing in 2025?

A security-minded look at the rimraf npm package — what it does, why old versions throw deprecation warnings, and when Node's built-in fs.rm makes it optional.

May 9, 20266 min read
Product

npm/package health and quality scoring methodology

How npm package health scores are calculated, why Socket.dev's model misses live supply chain attacks, and what Safeguard checks instead.

May 8, 20267 min read
Product

Minimum release age / cooldown policies for new package v...

A cooldown on new npm package versions can block malicious releases before they reach your build. Here's how minimum release age policies work.

May 7, 20269 min read
Security

CVE-2022-3509: The protobuf-java DoS Vulnerability Explained

CVE-2022-3509 is a denial-of-service flaw in protobuf-java's text-format parser that lets crafted input trigger long garbage-collection pauses. Here is who is affected and how to fix it.

May 5, 20265 min read
Open Source

react-query (TanStack Query): Package Health and Data-Fetching Safety

The npm react-query package froze at v3.39.3 when the project moved to @tanstack/react-query. Here is how to tell which one you are running, and how to keep server-state caching from leaking data.

May 4, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

dependency-management (Page 8) — Safeguard Blog