maven
Safeguard articles tagged "maven" — guides, analysis, and best practices for software supply chain and application security.
38 articles
The Java ecosystem's recurring vulnerability classes: deserialization, XXE, and JNDI injection
Log4Shell scored a 10.0 CVSS and Spring4Shell followed five months later — both traced back to two patterns Java has repeated for a decade.
Generating CycloneDX and SPDX SBOMs from Java Projects with Maven and Gradle
CISA's 2025 draft update proposes four new fields on top of NTIA's minimum elements, from 7 to 11 — most Maven and Gradle-generated SBOMs still fail that bar.
Auditing and pinning transitive Java dependencies with Maven and Gradle
Maven resolves version conflicts by nearest path, not highest version — one new direct dependency can silently reintroduce a patched CVE.
Maven Dependency Security: Pinning, Verification, and Scanning
How to secure a Maven build in 2026 — pin versions, enforce convergence, verify artifacts, and scan the transitive tree that pom.xml never shows you.
Auditing Maven Dependencies with OWASP Dependency-Check
OWASP Dependency-Check is the classic way to scan Java and Maven projects against the NVD. Learn to run it, tame its false positives, and move beyond CPE matching.
spring-security-core Maven: Keeping Your Auth Layer Patched
The spring-security-core Maven artifact is the heart of authentication and authorization in Spring apps, and a handful of recent CVEs make version hygiene non-negotiable.
How Snyk resolves Maven and Gradle dependency graphs incl...
Snyk doesn't parse pom.xml or build.gradle statically -- it invokes real Maven and Gradle tooling to compute the exact dependency graph your build produces.
Java Supply Chain Security Beyond Log4Shell
Log4Shell was the fire drill. The structural problems — unverified Maven resolution, invisible shaded jars, sprawling transitive graphs — are still there. Here's what to actually fix.
Fixing vulnerabilities in Maven projects
Maven vulnerability remediation isn't just running mvn versions:use-latest — here's how to triage, patch, and verify fixes without breaking builds.
tomcat-embed-core in Maven: A Security Guide to CVEs and Fixes
The tomcat-embed-core Maven artifact is the embedded Tomcat engine inside most Spring Boot apps, and it has carried several serious CVEs. Here is how to find your version and patch it.
Java Vulnerability Scanner: How It Works and What to Use
A Java vulnerability scanner inspects your dependencies, bytecode, and running app for known CVEs and insecure patterns. Here is how each type works.
com.google.code.gson: Using Gson Safely in Modern Java
Why the com.google.code.gson group ID looks so odd, what maintenance mode means for the library, and the configuration habits that keep Gson safe in modern Java services.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.