Safeguard
Tag

sast

Safeguard articles tagged "sast" — guides, analysis, and best practices for software supply chain and application security.

100 articles

Buyer's Guides

Evaluate a Security Scanner in Three Weeks, Not Six Months

A standard bake-off measures detection on code both tools have seen, weights forty rows equally, and tests week one of a week-fifty problem. Six questions with real variance, and how to run them against your incumbent too.

Sep 17, 20266 min read
Application Security

Second-Order SQL Injection Is the Bug Class a Scanner Should Refuse to Test

For a stored injection, confirming the bug and exploiting it are the same action. That is a property of the vulnerability, not a gap in anyone's product, and it changes what you should ask a DAST vendor.

Sep 17, 20267 min read
Application Security

The One Line of Ordinary Code That Kills a Taint Engine

param = decode(param) is as common as code gets. In a dataflow engine that resolves variables by looking backwards, it can recurse forever — and in Go the resulting stack overflow cannot be caught.

Aug 18, 20265 min read
Application Security

Reading an OWASP Benchmark Score Without Being Sold To

A tool that flags every test case scores 100% detection on the OWASP Benchmark. Recall is the number vendors quote and the one that means least — here is what the suite actually measures.

Aug 18, 20265 min read
AppSec

What Tree-sitter Taint Analysis Actually Catches (and What It Cannot)

Following untrusted data from source to sink across a real codebase is a solved problem right up until reflection, dynamic dispatch and an ORM turn up. Knowing where the analysis stops is what makes it usable.

Aug 15, 20265 min read
AppSec

Recall Is Easy. Your SAST Tool's Real Metric Is the Mute Rate

Any scanner can find every vulnerability by flagging everything. The number that decides whether a tool survives contact with a development team is how often it is wrong.

Aug 15, 20265 min read
AppSec

Running the OWASP Benchmark Against Your Own SAST Engine

A scanner with no measured accuracy is a scanner with claimed accuracy. Wiring up the OWASP Benchmark gives you one number that survives scrutiny — and usually finds a crash on the way.

Aug 15, 20266 min read
AI Security

Your Git History Already Knows Which AI Wrote Your Code

Coding assistants sign their own work in the commit trailer block. That makes 'how much of this was AI-written' a parsing problem, not a heuristic one — as long as your tooling reads the commit body, which most of it does not.

Aug 13, 20265 min read
Application Security

AI Writes Code Faster Than You Can Review It. Which Scanner Do You Point at It?

AI-generated code arrives faster than review can absorb and fails in distinct patterns. SAST, DAST, and reachability each catch part of that — and each misses a specific, predictable slice.

Aug 9, 20266 min read
Vulnerability Analysis

Open redirect vulnerabilities explained

Open redirect flaws (CWE-601) score as medium severity alone, but they power real phishing campaigns against Google, Amex, and Microsoft. Here's how they work and how to stop them.

Aug 3, 20267 min read
Vulnerability Analysis

Type confusion vulnerabilities explained

Type confusion bugs let attackers corrupt memory by exploiting mismatched type assumptions. See real CVEs, how JIT engines fail, and how to catch it early.

Aug 2, 20266 min read
Vulnerability Analysis

Format string vulnerabilities explained

Format string bugs let attackers turn a printf call into memory disclosure or arbitrary writes. Here's how CWE-134 works, real CVEs, and fixes.

Aug 2, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.