dependency-security
Safeguard articles tagged "dependency-security" — guides, analysis, and best practices for software supply chain and application security.
95 articles
jsonwebtoken npm: Security Review and Safe Usage
The jsonwebtoken npm package signs and verifies JWTs for countless Node apps, and versions at or below 8.5.1 carry serious verification flaws. Here is how to use npm jsonwebtoken safely.
Repojacking
Aqua Security found nearly 37,000 GitHub repos vulnerable to repojacking, including Google and Lyft. Here's how the attack works and how Safeguard catches it.
Jakarta and Java: A Security Guide to the Namespace Migration
Jakarta Java is the successor to Java EE, and the javax-to-jakarta namespace shift has real security implications for anyone still running the old libraries.
Is npm body-parser Safe? A Security Review and Safe-Usage Guide
A practical look at npm body-parser, the CVE-2024-45590 denial-of-service issue, and how to configure the middleware so it does not become a liability in production.
npm rollup: A Security Review and Safe Usage Guide
A practical look at what installing rollup from npm means for your supply chain, the DOM clobbering XSS bug you should know about, and how to pin a safe version.
Is the Cheerio npm Package Safe? A Security Review
A practitioner's look at the cheerio npm package: what it does, where its real security risk lives, and how to use it safely in production scrapers and parsers.
Is react-json-view Safe to Use? A Security Guide
The original react-json-view package is popular but unmaintained. Here is what that means for your app's security and which fork to move to.
What is a Software Supply Chain Attack
A software supply chain attack compromises trusted dependencies or build systems to spread malicious code downstream — here's how it works, and how to stop it.
class-validator: Security, Health, and Safe Usage in Production
class-validator powers input validation in most NestJS apps, but its defaults burned teams once before. Here is its real security history and how to configure it safely.
Known Vulnerabilities in Dependencies
Known vulnerabilities in dependencies cause most supply-chain breaches, not because they're undetected but because teams can't tell which ones are reachable.
undici npm: Security Review and Safe Usage
The undici npm package is Node.js's modern HTTP client and the engine behind the built-in fetch. Here is a review of its security history and how to keep npm undici patched.
Installing Python on Mac Safely: A Security Guide
Installing Python para Mac the wrong way leaves you patching the system interpreter and running sudo pip. Here is the secure, maintainable setup for Python on macOS.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.