dependency-management
Safeguard articles tagged "dependency-management" — guides, analysis, and best practices for software supply chain and application security.
197 articles
How to Check for npm Vulnerabilities (and Actually Fix Them)
npm check vulnerabilities the right way: what npm audit tells you, where it misleads, and how to turn a wall of advisories into a short list of things worth fixing.
react-native-inappbrowser-reborn: A Security Review of the In-App Browser Package
A practitioner's security look at react-native-inappbrowser-reborn: what it does, where the risk lives, and how to vet it and siblings like react-native-wifi-reborn.
netty-codec-http2 in Maven: Vulnerabilities and Fixes
The netty-codec-http2 Maven artifact powers HTTP/2 in gRPC, Spring, and countless services. Here are the CVEs that matter, the safe versions, and how to find it in your tree.
Socket.dev vs Dependabot: beyond automated dependency upd...
Dependabot patches known CVEs; Socket.dev flags risky package behavior. Neither enforces policy or ties risk to your actual build and runtime footprint — here's where Safeguard fits.
What Makes a Good Open Source Security Platform?
An open source security platform has to cover the whole dependency lifecycle, not just print CVEs. Here is what the category actually includes and how to evaluate one for your stack.
Runbooks for Dependency Disclosure Events
Detailed runbooks for responding to dependency CVE disclosures across languages and ecosystems, with roles, commands, and timelines tuned for automation.
PHP Security Issues: The Vulnerabilities That Still Bite in 2025
Most PHP security issues come down to a handful of repeatable mistakes: unsanitized input, weak session handling, and outdated dependencies. Here is what breaks and how to fix it.
Rimraf npm: Is It Still Worth Installing in 2025?
A security-minded look at the rimraf npm package — what it does, why old versions throw deprecation warnings, and when Node's built-in fs.rm makes it optional.
npm/package health and quality scoring methodology
How npm package health scores are calculated, why Socket.dev's model misses live supply chain attacks, and what Safeguard checks instead.
Minimum release age / cooldown policies for new package v...
A cooldown on new npm package versions can block malicious releases before they reach your build. Here's how minimum release age policies work.
CVE-2022-3509: The protobuf-java DoS Vulnerability Explained
CVE-2022-3509 is a denial-of-service flaw in protobuf-java's text-format parser that lets crafted input trigger long garbage-collection pauses. Here is who is affected and how to fix it.
react-query (TanStack Query): Package Health and Data-Fetching Safety
The npm react-query package froze at v3.39.3 when the project moved to @tanstack/react-query. Here is how to tell which one you are running, and how to keep server-state caching from leaking data.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.