open-source-security
Safeguard articles tagged "open-source-security" — guides, analysis, and best practices for software supply chain and application security.
371 articles
ROI of automated dependency management (Renovate Enterprise)
Automated dependency updates promise real ROI, but Renovate Enterprise's PR-scheduling model often stalls at the review bottleneck. Here's how to measure the real numbers.
Malicious packages and malware campaigns: the new reality...
Malicious open source packages don't wait for a CVE. See how npm worms, xz utils, and typosquats evade legacy SCA — and what real detection requires.
react-native-encrypted-storage: A Practical Security Guide
What react-native-encrypted-storage does, how it wraps iOS Keychain and Android EncryptedSharedPreferences, its maintenance status, and how it compares to react-native-secure-storage.
First-Party Code vs Open Source Risk: Where Should AppSec...
First-party code and open source dependencies are one attack surface. See how Safeguard's unified scanning compares to Endor Labs' open-source-first approach.
Dependency Cooldown Periods as a Malware Defense
Malicious npm packages are often caught within days. Cooldown periods exploit that lag — here's how they work, and how Endor Labs and Safeguard compare.
Snyk Dependency Scanning: How It Works, Its Limits, and Alternatives
A fair look at Snyk dependency scanning: what it does well, how its test-based pricing works, where teams hit limits, and how to decide if it fits your workflow.
What SCA Means in Security (Software Composition Analysis)
The SCA security meaning explained: what software composition analysis is, how it differs from SAST and DAST, and why it matters for the open source in your code.
What Is a Mend Scan and How Does It Work?
A Mend scan analyzes your open-source dependencies and code for known vulnerabilities and license risk. Here is what it covers and how to run one in CI.
How to Check for npm Vulnerabilities (and Actually Fix Them)
npm check vulnerabilities the right way: what npm audit tells you, where it misleads, and how to turn a wall of advisories into a short list of things worth fixing.
EU Cyber Resilience Act: what developers need to know
The EU Cyber Resilience Act sets hard deadlines starting Sept 2026 for SBOMs, vulnerability reporting, and patching. Here's what developers must build.
Rimraf npm: Is It Still Worth Installing in 2025?
A security-minded look at the rimraf npm package — what it does, why old versions throw deprecation warnings, and when Node's built-in fs.rm makes it optional.
What is the BSD license? Top 10 questions answered
The BSD license explained: its 0-, 2-, 3-, and 4-clause variants, how it differs from MIT and GPL, and which real projects run on it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.