devsecops
Safeguard articles tagged "devsecops" — guides, analysis, and best practices for software supply chain and application security.
868 articles
Docker Privileged Containers: `docker run` and Compose Risks
docker run privileged and docker compose privileged both hand a container root-equivalent access to the host — here's exactly what that means and when, if ever, it's justified.
How to reduce alert fatigue from vulnerability scanners
Container scanners like Trivy can return thousands of CVE findings per scan. Here's why most are noise, and how reachability and exploit data cut the list to what matters.
Choosing a Private Package Registry in 2025
A 2025 buyer's guide comparing JFrog Artifactory, Sonatype Nexus, GitHub Packages, Google Artifact Registry, and Cloudsmith on ecosystems, policy, and TCO.
Python unittest.mock: A Practical Guide with Security in Mind
Python's unittest.mock lets you test the code you would never dare run for real — including the security-critical failure paths that never fire in a happy-path test.
Code Quality Tools That Also Strengthen Your Security
Code quality tools do more than catch style nits; the good ones surface the same weak patterns that turn into vulnerabilities. Here is how quality tooling and security overlap, with a focus on Java.
Python on macOS: A Security-Minded Setup Guide
Running Python on Mac OS is easy to get wrong in ways that bite you later. Here is how to install and isolate Python for Mac OS without the common security traps.
Annual DevSecOps maturity benchmark report
Safeguard's 2026 DevSecOps Maturity Benchmark finds detection at an all-time high but remediation stuck at a 19-day median — here's what separates the top-quartile programs.
Developer survey: security friction in the SDLC
A new Safeguard survey of 540 developers finds most have shipped code with known security warnings, driven by alert fatigue and manual SBOM work.
Enso Security and ASPM: What It Is and Why It Matters
Enso Security pioneered Application Security Posture Management before its 2023 acquisition by Snyk. Here is what ASPM solves and how the category has evolved.
Agentless vs. agent-based cloud security: which approach ...
Agentless cloud scanning and pipeline-based supply chain security aren't the same tradeoff. Here's how Safeguard's build-time approach compares to Wiz's agentless model.
Choosing a Tool to Detect Security of Code: What Each Type Finds
There is no single tool to detect security of code. Here is what SAST, SCA, secret scanning, DAST, and IaC scanning each catch, and how to combine them without drowning in alerts.
The Java Security Manager Is Deprecated: What to Use Instead
JEP 411 deprecated the Java Security Manager for removal, and years of accumulated java security flaws in its trust model are why the platform is retiring it rather than fixing it further.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.