dependency-risk
Safeguard articles tagged "dependency-risk" — guides, analysis, and best practices for software supply chain and application security.
22 articles
@typescript-eslint/typescript-estree: A Security Review
A security review of @typescript-eslint/typescript-estree: what the parser does, where its real risk lives (its dependencies, not itself), and how to keep it safe.
react-sortable-hoc: Security and Maintenance Status Review
react-sortable-hoc is no longer actively maintained and leans on the soon-to-be-removed findDOMNode API. Here's what that means for your risk and what to migrate to.
react-signature-canvas: A Security and Maintenance Review
A security review of react-signature-canvas: what the component does, its inactive maintenance status, the XSS surface to watch, and how to use it safely.
react-native-modal-datetime-picker: Security and Maintenance Guide
The react-native-modal-datetime-picker package is popular and convenient, but its maintenance status and transitive dependencies deserve a look before you commit to it.
angular-ui-router: Security and Maintenance Guide
angular-ui-router is the classic routing library for AngularJS 1.x. The library itself is stable, but the framework it depends on reached end of life, and that is the real risk to weigh.
pdfmake npm: A Security Review and Safe Usage Guide
pdfmake is a popular client and server PDF generator, but its dependency chain and server-side usage carry real risks. Here is a practical security review.
rn-fetch-blob: Maintenance Status, Risks, and Alternatives
The rn-fetch-blob npm package hasn't shipped a release since 2020. Here's what that means for React Native apps still depending on it, and how to migrate to react-native-blob-util.
React File Viewer: Is It Safe, and What Are the Alternatives?
react-file-viewer still gets thousands of weekly downloads despite going years without an update. Here is what the package does, the risks of a dormant dependency, and how to view files more safely.
awesome-typescript-loader: Why to Migrate Off It
awesome-typescript-loader is an unmaintained webpack loader for TypeScript. Here is the security case for migrating to ts-loader and how to do it cleanly.
Abandoned Package Takeover: When Maintainers Walk Away
Abandoned packages are ticking time bombs in the supply chain. When maintainers disappear, attackers can take over package names and push malicious updates to millions of downstream projects.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.