Safeguard
Tag

dependency-risk

Safeguard articles tagged "dependency-risk" — guides, analysis, and best practices for software supply chain and application security.

22 articles

AI Security

How slopsquatting exploits AI-hallucinated package names

Slopsquatting attacks turn AI-hallucinated package names into real supply chain threats. Here's how it works, the numbers behind it, and how Safeguard stops it.

Aug 3, 20267 min read
Open Source Security

Unmaintained Open Source Software: A Supply Chain Risk

Unmaintained open source components quietly power critical software until a bug hits and no one is left to patch it. Here's the risk, and how to manage it.

Jul 8, 20267 min read
Buyer's Guides

Checkmarx vs Snyk: which AppSec platform fits your stack

Checkmarx vs Snyk searches usually miss the real question: does your AppSec stack cover source code, or the full build-to-deploy supply chain? Here's how to check.

Jun 27, 20268 min read
Open Source

pdf-lib npm: A Security Review and Safe Usage Guide

pdf-lib is a popular pure-JavaScript library for creating and editing PDFs, with no known direct vulnerabilities but an inactive maintenance status worth planning around.

Jun 18, 20266 min read
Open Source Security

How Snyk Advisor's package health score weighs popularity...

Snyk Advisor scores packages 0-100 using four signals: popularity, maintenance, community, and security. Here is exactly how each one is calculated.

Jun 9, 20267 min read
Open Source

react-native-video-processing: Status, Risks, and Alternatives

A security-minded look at react-native-video-processing: what the library does, its maintenance status, the native dependency risk, and what to use instead.

Jun 2, 20266 min read
Open Source Security

The Long Tail of Abandoned Open Source Projects and Enter...

Abandoned open source packages sit quietly in enterprise SBOMs until a burned-out maintainer, a hijacked account, or a patient attacker turns them into the next supply chain incident.

Jun 2, 20267 min read
Open Source Security

The Economics of Free Riding in Open Source Security

Open source runs on unpaid labor while billion-dollar companies use it for free. Here's the economics behind Log4Shell, xz-utils, and the free rider problem.

Jun 1, 20268 min read
Open Source Security

Security Training Gaps Among Solo Maintainers of High-Imp...

xz-utils, event-stream, and ua-parser-js show how single-maintainer projects lack the security training and support that high-impact infrastructure now demands.

May 26, 20267 min read
Open Source Security

Measuring Project Health: Bus Factor, Commit Velocity, an...

Bus factor, commit velocity, and maintainer concentration predicted the xz-utils and event-stream incidents before any CVE did. Here's how to read these proxies — and where they mislead.

May 26, 20269 min read
Security

@typescript-eslint/typescript-estree: A Security Review

A security review of @typescript-eslint/typescript-estree: what the parser does, where its real risk lives (its dependencies, not itself), and how to keep it safe.

May 16, 20265 min read
Open Source

react-sortable-hoc: Security and Maintenance Status Review

react-sortable-hoc is no longer actively maintained and leans on the soon-to-be-removed findDOMNode API. Here's what that means for your risk and what to migrate to.

May 11, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

dependency-risk — Safeguard Blog