product
Safeguard articles tagged "product" — guides, analysis, and best practices for software supply chain and application security.
18 articles
Fast, Deep, or Proactive: Choosing the Right Scan for the Moment
Safeguard's three scan modes trade speed, depth, and continuous coverage differently. Here is when to reach for each one in a real CI/CD pipeline or periodic audit cadence.
Meeting Your Team Where They Already Work
Web app, desktop app, mobile app, local runner CLI, IDE extensions, browser extensions, MCP server, SDKs, CI/CD actions, and chat integrations: Safeguard is built to show up inside the tools your team already uses.
Autonomous Remediation: The Eight Categories Explained
Safeguard's Autonomous Remediation spans eight independent categories, from dependencies to compliance, each with its own strategy. It ships off by default, and that is a deliberate trust-building choice, not a limitation.
Safeguard Is Now in Your Browser: the Chrome Extension Is Live
One click on the Chrome Web Store puts Griffin AI search in a side panel next to any tab — one permission, no host access, no data collection, under 8 KiB. Here's what it does and why we built it so small.
What's New: Live Agentic Search, a Real Trust Center, and Safeguard in Your Browser
A tour of this month's releases — watching Griffin work in real time, publishing your security posture and artifacts to a governed Trust Center, and reaching Safeguard from the browser, CLI, IDE, and MCP.
Introducing the Package Firewall and AI Model-Artifact Scanning
Two supply-chain defenses are rolling out on Safeguard: an install-time Package Firewall that blocks malicious npm and pip packages before they resolve, and AI model-artifact scanning that inspects model weights — now including ONNX — for malware before they load.
GitHub Advanced Security setup made simple: guided config...
GitHub Advanced Security setup takes weeks, not clicks. Here's what GHAS configuration really involves, what it costs in 2026, and how Safeguard cuts the tuning work.
How the Snyk Language Server powers IDE plugins across VS...
A technical look at how Snyk's Go-based Language Server uses LSP and a delegating scanner pattern to power VS Code, JetBrains, and Eclipse plugins from one binary.
How Snyk's GitHub Actions integration scans pull requests...
A mechanical breakdown of how Snyk's GitHub Actions integration scans pull requests: triggers, SARIF uploads, severity thresholds, and what the checks can't see.
How the Snyk CLI's --all-projects flag discovers manifest...
A technical look at how Snyk CLI's --all-projects flag walks a repository, matches manifest files, and where directory-depth limits can leave dependencies unscanned.
Reachability analysis for vulnerability prioritization
Most CVEs your scanner flags are never executed. See how reachability analysis filters noise, how Socket.dev approaches it, and how Safeguard finds real risk.
Real-time threat feed for open source malware detection
Malicious npm and PyPI packages spread in hours, not days. Here's why real-time threat feeds beat periodic scans, and how Safeguard detects supply chain malware before install.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.