dependency-security
Safeguard articles tagged "dependency-security" — guides, analysis, and best practices for software supply chain and application security.
95 articles
jsonwebtoken npm: Security Review and Safe Usage
The jsonwebtoken npm package signs and verifies JWTs for countless Node apps, and versions at or below 8.5.1 carry serious verification flaws. Here is how to use npm jsonwebtoken safely.
Jakarta and Java: A Security Guide to the Namespace Migration
Jakarta Java is the successor to Java EE, and the javax-to-jakarta namespace shift has real security implications for anyone still running the old libraries.
Is npm body-parser Safe? A Security Review and Safe-Usage Guide
A practical look at npm body-parser, the CVE-2024-45590 denial-of-service issue, and how to configure the middleware so it does not become a liability in production.
Is the Cheerio npm Package Safe? A Security Review
A practitioner's look at the cheerio npm package: what it does, where its real security risk lives, and how to use it safely in production scrapers and parsers.
npm rollup: A Security Review and Safe Usage Guide
A practical look at what installing rollup from npm means for your supply chain, the DOM clobbering XSS bug you should know about, and how to pin a safe version.
Is react-json-view Safe to Use? A Security Guide
The original react-json-view package is popular but unmaintained. Here is what that means for your app's security and which fork to move to.
class-validator: Security, Health, and Safe Usage in Production
class-validator powers input validation in most NestJS apps, but its defaults burned teams once before. Here is its real security history and how to configure it safely.
undici npm: Security Review and Safe Usage
The undici npm package is Node.js's modern HTTP client and the engine behind the built-in fetch. Here is a review of its security history and how to keep npm undici patched.
Installing Python on Mac Safely: A Security Guide
Installing Python para Mac the wrong way leaves you patching the system interpreter and running sudo pip. Here is the secure, maintainable setup for Python on macOS.
python-multipart Security: Patching the Form-Data DoS
Why the python-multipart parser behind FastAPI and Starlette had a denial-of-service flaw, how to check your version, and how to keep form uploads safe.
npm dd-trace: Security Review and Safe Usage
The npm dd-trace package is Datadog's Node.js APM tracer. It runs deep in your process, so here is an honest look at its security posture and how to deploy it safely.
Choosing an npm XML Parser: Security Comparison and XXE Pitfalls
Not every npm XML parser carries the same risk. We compare xml2js, fast-xml-parser, sax, and libxmljs on their CVE history, XXE exposure, and safe configuration.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.