frontend-security
Safeguard articles tagged "frontend-security" — guides, analysis, and best practices for software supply chain and application security.
38 articles
Your Feature Flag Targeting Rules Are Visible in the Browser
To evaluate flags locally, the client-side SDK needs the targeting rules: which accounts get the enterprise preview, the pricing tier conditions, the churn-risk exclusions. Open the network panel and anyone can read all of it.
What Leaves Your Application When a User Clicks a Link
The address of the page they were on, and sometimes a handle that lets the destination navigate your tab. Both are defaults, both are one attribute away from fixed, and your URLs contain identifiers and sometimes capabilities.
Watch Your Own Session Replay and Read Every Field
The recording is a reconstruction of the rendered page, so anything that reached the browser is a candidate, not just what the user typed. Masking covers the fields somebody remembered to cover.
What Is the Bootstrap Latest Version, and Is It Secure?
The Bootstrap latest version is 5.3.8, and knowing your version is a security decision: older Bootstrap releases carry known XSS bugs and rely on end-of-life jQuery.
React Security Best Practices: A Practical Checklist for 2026
React escapes JSX text for you, but XSS sinks, secrets in the client bundle, token storage, and a 500-package npm worm are still yours to handle.
browser-image-compression: Is Client-Side Image Compression Safe?
browser-image-compression shrinks images in the browser before upload. Here is how it works, its security trade-offs, and why client-side compression is never validation.
ngx-bootstrap Security: What to Know After the 2025 npm Compromise
ngx-bootstrap is a popular Angular component library that was hit by a real npm supply-chain attack in September 2025. Here is what happened, what to check, and how to use it safely.
Angular Compiler Security: What @angular/compiler-cli Handles and How to Keep It Safe
The Angular compiler is more than a build step — it enforces your template sanitization contract, and a 2025 XSS bug proved that assumption can break.
localStorage Security: Why You Shouldn't Keep Tokens There
localStorage security comes down to one fact: any script on your page can read it. That makes it the wrong place for auth tokens and anything sensitive.
CVE-2022-31160: Understanding the jQuery UI Checkboxradio XSS
CVE-2022-31160 is a cross-site scripting flaw in jQuery UI's checkboxradio widget, fixed in 1.13.2. Here is how it works and how to remediate it.
Webpack 5 Node Polyfills: node-polyfill-webpack-plugin Explained
node-polyfill-webpack-plugin restores the Node core shims webpack 5 removed. Before you install it, understand what you are re-adding to your bundle and why webpack removed it.
Antd Injection: Preventing XSS in Ant Design Applications
Antd injection risk is not a flaw in the component library itself but in how you feed it untrusted data. Here is where the danger lives and how to close it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.