Safeguard
Tag

devsecops

Safeguard articles tagged "devsecops" — guides, analysis, and best practices for software supply chain and application security.

868 articles

Security

Checkmarx Careers: What a Career in Application Security Involves

Curious about Checkmarx careers or breaking into AppSec generally? Here is what these roles actually involve, the skills that matter, and how to prepare.

Apr 28, 20266 min read
DevSecOps

GitHub secret scanning vs dedicated scanning tools

GitHub secret scanning vs Trivy: how push protection, validity checks, and multi-source coverage differ, and where Safeguard fits for cross-repo remediation.

Apr 28, 20267 min read
Security

How Application Security Risk Management Actually Works in Practice

A working model for application security risk management: how to inventory assets, rate risk you can act on, prioritize by exploitability and impact, and prove the program is reducing risk.

Apr 28, 20267 min read
AppSec

Open Source SAST Tools Worth Evaluating

A rundown of the open source SAST tools engineering teams actually use in production, and where each one runs out of road.

Apr 26, 20265 min read
Container Security

Container image scanning: how it works and best tools

A practical guide to container image scanning: how layer-by-layer CVE detection works, how Trivy stacks up, and where Safeguard adds deeper coverage.

Apr 26, 20267 min read
Container Security

Container security best practices checklist

A practical container security checklist covering base images, scanning limits, runtime risk, and why CVE scans like Trivy alone miss most real supply chain threats.

Apr 26, 20267 min read
DevSecOps

vite-plugin-node-polyfills: A Security-Minded Setup Guide

vite-plugin-node-polyfills injects browser shims for Node built-ins so npm packages that expect Buffer or process work in Vite. Convenient, but every polyfill you add is code that ships.

Apr 25, 20265 min read
Software Supply Chain Security

Software supply chain attacks: how they work and recent e...

Software supply chain attacks like SolarWinds, xz-utils, and polyfill.io bypass vulnerability scanners entirely. Here's how they work and where provenance verification fills the gap.

Apr 25, 20268 min read
Industry Analysis

The State of Cloud Native Application Security survey

New 2026 survey data reveals a widening gap between vulnerability alert volume and remediation capacity — and what security teams say actually helps.

Apr 25, 20267 min read
Software Supply Chain Security

PulseMeter report: software supply chain risk perceptions

Safeguard's latest PulseMeter survey finds 71% of teams hit a supply chain incident this year, but only 34% feel confident they'd catch one in time.

Apr 25, 20267 min read
DevSecOps

MagicMock in Python: Safe Testing and the Traps to Avoid

MagicMock in Python makes tests easy to write and easy to make lie. Here is how it differs from Mock and how to keep mocks from hiding real security bugs.

Apr 25, 20265 min read
DevSecOps

Git Checkout Dev: Switching to a Development Branch Safely

git checkout dev switches your working tree to the dev branch, but the safe workflow around it matters more than the command. Here is how to do it without losing work or leaking secrets.

Apr 24, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

devsecops (Page 38) — Safeguard Blog