sast
Safeguard articles tagged "sast" — guides, analysis, and best practices for software supply chain and application security.
377 articles
How Snyk Code's duplicate and similar-code detection supp...
Snyk Code once shipped duplicate and similar-code detection under its Code Quality rules. Here's how it worked, and what its 2025 retirement means for teams.
5 best practices for adopting GitHub Copilot securely
GitHub Copilot has 1.3M+ paid seats. Five concrete, evidence-based practices for locking down content exclusion, licensing, code quality, and prompt injection risk.
GenAI Code Review Tools: A 2025 Field Test
We field-tested five GenAI code review tools against 240 seeded security defects to see which catch real issues and which hallucinate findings.
DevSecOps Technology: The Tools and Practices That Actually Work
DevSecOps technology is the stack of tools and automation that embeds security into the software delivery pipeline. Here is what the categories are and how they fit together.
A Checkmarx Scan: What It Actually Analyzes
A breakdown of what a Checkmarx scan actually analyzes under the hood, what its static analysis engine catches well, and where teams typically add another tool alongside it.
Type-level security: the future of secure AI code generation
45% of AI-generated code fails basic security tests. Here's why type systems catch what code review misses, and how to enforce type-level security on AI-authored diffs.
Checkmarx Documentation: A Guide to Navigating It
Checkmarx documentation is deep but sprawling. Here is how to find what you need across SAST, the APIs, and integrations without losing an afternoon.
What Makes a Strong Application Security Solution
An application security solution is not a single scanner but a coordinated set of controls across the software lifecycle. Here is what a real one covers.
Snyk VulnBench: benchmarking LLMs on repeat vulnerability discovery
Snyk's VulnBench JS 1.0 ran 300 repeated LLM scans and found half of non-reference findings vanish on rerun—raising the bar for AI security tooling.
SQL Injection Test: How to Safely Check Your App for SQLi
A SQL injection test proves whether user input can reach your database as code. Here is how to test your own applications responsibly, read the results, and fix what you find.
Choosing a Python Tool for Security: Scanning and Hardening Python Code
The right Python tool depends on what you are trying to catch: bugs in your own code, vulnerable dependencies, or leaked secrets. Here is how the categories fit together.
Source Code Security Scanning Programs That Scale
A source code security scanning program that works for 20 repos usually breaks at 200 — here's how to design one that scales with the number of teams, not just the number of scans.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.