dependency-security
Safeguard articles tagged "dependency-security" — guides, analysis, and best practices for software supply chain and application security.
95 articles
python-multipart Security: Patching the Form-Data DoS
Why the python-multipart parser behind FastAPI and Starlette had a denial-of-service flaw, how to check your version, and how to keep form uploads safe.
npm dd-trace: Security Review and Safe Usage
The npm dd-trace package is Datadog's Node.js APM tracer. It runs deep in your process, so here is an honest look at its security posture and how to deploy it safely.
Choosing an npm XML Parser: Security Comparison and XXE Pitfalls
Not every npm XML parser carries the same risk. We compare xml2js, fast-xml-parser, sax, and libxmljs on their CVE history, XXE exposure, and safe configuration.
follow-redirects: Known Vulnerabilities and How to Stay Patched
follow-redirects sits under axios in millions of Node apps. A practical guide to its CVE history and how to keep the pinned version current.
Is the got npm Package Safe? A Security Review of got for Node.js
got is a well-maintained HTTP client, but one redirect-handling CVE and its SSRF-prone defaults are worth knowing before you ship it. Here is the security review.
Is the npm Luxon Package Safe to Use? A Security Review
The npm Luxon package is actively maintained and safe for current use, with one notable historical ReDoS advisory to be aware of. Here is the security picture.
JSON Patch Security: Prototype Pollution and Safe Usage
JSON Patch (RFC 6902) is a compact format for applying partial updates, but implementations like fast-json-patch have had prototype-pollution flaws. Here is how to use it safely.
minimatch npm: Security Review and Safe Usage
The minimatch npm package powers glob matching across the JavaScript ecosystem, and a ReDoS flaw made older versions a denial-of-service risk. Here is what to know and how to stay safe.
Best SCA Tools for Enterprise: 2026 Comparison
A fact-based 2026 review of the best Software Composition Analysis tools for enterprise teams, covering depth, reachability, remediation, and compliance.
Slopsquatting (AI package hallucination attack)
Slopsquatting exploits AI coding assistants that hallucinate nonexistent package names, which attackers then register as real, malicious packages.
The event-stream npm Attack Explained
In 2018, a hijacked npm maintainer account turned event-stream into a supply chain weapon against crypto wallets. Here's the full CVE-style breakdown.
Go module proxy security: how GOPROXY and sum.golang.org ...
How GOPROXY and sum.golang.org protect Go builds with caching and checksum verification, and where trust-on-first-use gaps let malicious modules slip through.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.