Tag
package-manager
Safeguard articles tagged "package-manager" — guides, analysis, and best practices for software supply chain and application security.
2 articles
Open Source Security
npm v12 Disabled Install Scripts. Attackers Adapted in Three Days.
On 8 July 2026 npm v12 shipped with install scripts off by default — closing what GitHub called the ecosystem's largest code-execution surface. By 11 July, the jscrambler payload was executing on import instead. A study in why one-vector mitigations buy days, not years.
Jul 28, 20266 min read
Open Source Security
What is a Package Manager
Package managers like npm and pip automate dependency resolution — and have been the entry point for incidents from event-stream to the xz-utils backdoor.
Feb 8, 20267 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.