developer-tools
Safeguard articles tagged "developer-tools" — guides, analysis, and best practices for software supply chain and application security.
12 articles
Metro4Shell: React Native's Development Server Exposed to Anyone on the Network
CVE-2025-11953 lets unauthenticated attackers run arbitrary commands on developer machines through React Native's Metro Development Server, which binds to external interfaces by default.
Safeguard CLI v5: Faster, Smarter, More Extensible
Safeguard CLI v5 brings a rewritten scanning engine, plugin architecture, and native CI/CD integration. Here is what is new and how to upgrade.
AI Developer Tools: Weighing Productivity Against Security and IP Exposure
NYU found 40% of Copilot-generated code contained exploitable flaws; Samsung banned ChatGPT after three leaks in under 20 days. The productivity math still isn't simple.
Safeguard Desktop App: Supply Chain Security Without the Browser Tab
Announcing the Safeguard Desktop App -- a native application for macOS, Windows, and Linux that brings SBOM management, vulnerability tracking, and policy gates to your desktop.
MCP Inspector CVE-2025-49596: Anatomy of a 9.4 RCE in Anthropic's Reference Tool
A missing auth check in MCP Inspector versions below 0.14.1 let any website pop a shell on a developer's machine. Here is the full chain and what to fix.
How to Install the Snyk CLI (npm, Homebrew, and Standalone Binary)
Step-by-step ways to install the Snyk CLI on macOS, Linux, and Windows using npm, Homebrew, Scoop, or a standalone binary, plus how to authenticate and use it in CI.
How Do You Pronounce Snyk? The Definitive Answer
Snyk is pronounced sneak, like the verb. Here is where the name comes from, why people get it wrong, and what the tool actually does.
Safeguard IDE Extension v5: Security Feedback Where Developers Actually Work
The Safeguard IDE Extension v5 brings SBOM generation, vulnerability alerts, and policy checks directly into VS Code and JetBrains IDEs. A deep dive into what changed and why it matters.
How to Pronounce Snyk (and Other Security Tool Names People Get Wrong)
The correct answer to how to pronounce Snyk, plus a rundown of the other AppSec tool names — Nginx, Kubernetes, Grype — that trip people up in meetings.
Griffin AI vs Gemini On-Device: Developer Tools
Gemini on-device models are fast and cheap. For the developer-tool layer, they're useful. For the engine-plus-LLM layer, on-device is not the right fit.
DevEx Meets DevSecOps: Why Developer Experience Determines Security Outcomes
Security tools that developers hate get bypassed. The organizations with the best security outcomes are the ones that treat developer experience as a security requirement.
GitHub's Supply Chain Security Features
A comprehensive look at GitHub's evolving supply chain security toolkit, from Dependabot to code scanning, and how these features are reshaping how developers manage dependency risk.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.