python-security
Safeguard articles tagged "python-security" — guides, analysis, and best practices for software supply chain and application security.
96 articles
Choosing a Python Tool for Security: Scanning and Hardening Python Code
The right Python tool depends on what you are trying to catch: bugs in your own code, vulnerable dependencies, or leaked secrets. Here is how the categories fit together.
Dependency Confusion Attacks Five Years Later: Are Enterp...
Five years after Alex Birsan's $130K dependency confusion disclosure, real attacks like PyTorch's torchtriton incident show the flaw is still live. Here's what's actually fixed.
How to Choose a Python Code Checker for Secure Code
A Python code checker is more than a linter. Here is how the layers fit together, which open-source tools do what, and where online checkers help and hurt.
Is python-docx Safe? A Security Guide
python-docx reads and writes Word documents in Python. Here is what its security posture actually depends on, especially when you open files you did not create.
How to Build a Secure Python URL Validator (and Avoid SSRF)
A Python URL validator has to do more than match a regex. Here is how to validate URLs safely, block SSRF, and pick between urllib, validators, and Pydantic.
CVE-2022-2309: The lxml NULL Pointer Dereference DoS Explained
CVE-2022-2309 crashes lxml applications through a NULL pointer dereference in iterwalk. Here is the affected version matrix and how to remediate it.
Python Pickle Load: A Security Guide
Calling python pickle load on data you do not fully control can execute arbitrary code. Here is why, and what to use instead.
Is python.org Safe? What to Trust and What to Verify
The python.org website itself is the official, safe source for Python. The real risk lives one step downstream, on PyPI, where typosquatted packages wait for a typo.
Advanced Python: The Security-Focused Patterns Senior Developers Should Master
Advanced Python is not about clever one-liners. The patterns that separate senior engineers are the ones that keep code safe: safe deserialization, controlled subprocess calls, and disciplined dependency use.
flask-security-too: What It Is and How to Use It Securely
flask-security-too is the maintained successor to Flask-Security, giving Flask apps authentication, roles, and account features out of the box. Here is what it provides and how to configure it safely.
How to Open Python on Mac (and Do It Securely)
Recent macOS versions ship without Python at all, so opening Python on a Mac now means installing it yourself — and doing that safely matters more than most guides admit.
Tornado Python Security: Hardening Your Async Web App
A security-focused guide to the Tornado Python web framework, covering the cookie-parsing DoS, secure cookie configuration, and safe deployment patterns.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.