false-negatives
Safeguard articles tagged "false-negatives" — guides, analysis, and best practices for software supply chain and application security.
5 articles
A Clean Scan Usually Means the Scanner Did Not Look
Analysed your code and found nothing, or failed to analyse your code and therefore found nothing. Most tools report both as success. Seven reasons coverage collapses, and the canary dependency that proves a scan still works.
Five Places Reachability Analysis Says Unreachable and Is Wrong
Reachability is the best noise filter in dependency scanning and its failure mode is silence, not an error. The five cases where the call graph is incomplete, and what to do about each.
The One Line of Ordinary Code That Kills a Taint Engine
param = decode(param) is as common as code gets. In a dataflow engine that resolves variables by looking backwards, it can recurse forever — and in Go the resulting stack overflow cannot be caught.
False Positives vs False Negatives: What's the Difference?
A false positive flags something safe as dangerous. A false negative misses something dangerous entirely. One wastes your time; the other gets you breached.
False Positives vs False Negatives in Security Scanning
False positives in cyber security waste your team's time; false negatives get you breached. Here is how to think about the trade-off and tune for it deliberately.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.