javascript
Safeguard articles tagged "javascript" — guides, analysis, and best practices for software supply chain and application security.
93 articles
@microsoft/fetch-event-source: Robust SSE Streams in the Browser
The fetch event source library fixes everything the native EventSource API refuses to do: POST bodies, auth headers, and retry logic you actually control.
URL Validation in JavaScript: Regex Patterns and Safer Options
URL validation regex in JavaScript is tempting but brittle. Here are patterns that work, the ones that cause ReDoS, and why the URL constructor is usually the better tool.
core-js 2.6.12: Vulnerabilities, EOL Status, and Upgrading to v3
Searching for core-js 2.6.12 vulnerabilities turns up no CVEs — the finding is the abandoned v2 line itself. What the deprecation actually means and how to migrate to core-js 3 cleanly.
@babel/plugin-transform-runtime: What It Does and When You Need It
The babel plugin transform runtime deduplicates Babel's injected helpers and keeps polyfills out of the global scope. Here is what it actually changes in your output, and when it earns its place.
Is the npm Luxon Package Safe to Use? A Security Review
The npm Luxon package is actively maintained and safe for current use, with one notable historical ReDoS advisory to be aware of. Here is the security picture.
DOM-Based XSS Attacks: How They Work and How to Prevent Them
A DOM based XSS attack executes entirely in the browser, which is why your server-side filters and access logs never see it. Here is how the source-to-sink flow works and what actually stops it.
core-js on npm: Security Review and Safe Usage
A security and sustainability review of core-js on npm: the postinstall history, the maintainer funding crisis, and how to keep this near-universal dependency safe.
JSON Patch Security: Prototype Pollution and Safe Usage
JSON Patch (RFC 6902) is a compact format for applying partial updates, but implementations like fast-json-patch have had prototype-pollution flaws. Here is how to use it safely.
The xss npm Package: Sanitizing HTML Input Correctly
The xss npm package is a whitelist-based HTML sanitizer for Node and the browser. It works well — when you sanitize in the right place, with the right whitelist, for the right output context.
Ledger Connect Kit December 2023: A CDN Attack Retrospective
The Ledger Connect Kit compromise was a five-hour CDN attack that drained roughly $600k from connected wallets. A look at how it happened and what defenders learned.
JSR JavaScript Registry Security Model
JSR reimagines JavaScript package distribution with mandatory signing, scoped namespaces, and provenance by default. Here is how the security model works.
How to Detect Malicious npm Packages: A Workflow
A practical detection workflow for malicious npm packages: install-time signals, registry heuristics, reachability checks, and CI gates that actually block attacks.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.