Safeguard
Tag

sbom

Safeguard articles tagged "sbom" — guides, analysis, and best practices for software supply chain and application security.

100 articles

Software Supply Chain Security

A Lockfile Is Not a Control, the Install Command Is

You pinned every dependency with an integrity hash and committed the file. None of that means the artifact you shipped contains those versions, because several install commands are allowed to resolve differently and rewrite the lockfile.

Sep 18, 20266 min read
Incident Analysis

What to Tell Customers When a Dependency You Ship Is Compromised

The first message has to go out before the investigation finishes. What to say at each stage, the order that establishes scope, and why historical lockfiles turn a week of archaeology into a query.

Sep 17, 20266 min read
SBOM

The SBOM Your Customer Wants Is Not the One You Generated

An SBOM is a statement about a specific artifact. Generate it from the repository and you have an accurate document about something nobody runs, missing the base image where most of your published CVEs live.

Sep 17, 20266 min read
Compliance

The Seven Artifacts Every Enterprise Security Review Asks For

The customer security review is the most expensive gate in enterprise software sales and the most predictable. The same seven artifacts get requested in roughly the same order, and preparing them early turns nine weeks into two.

Sep 17, 20267 min read
Vulnerability Analysis

Patch Lag Explains the Old Breaches. It Does Not Explain the New Ones.

Reviewing two decades of major incidents, the ones that defined early security were patch-adoption failures. A growing share of recent ones had no patch to apply, because the compromise was in the distribution chain itself. These need different defences.

Sep 17, 20264 min read
Vulnerability Management

66,000 CVEs: The Year Enumeration Stopped Being a Strategy

2026 is forecast to close near 66,000 CVEs, driven partly by AI-assisted discovery. At that volume reading the list is not a job anyone can do — and most programmes are still built around reading it.

Aug 11, 20266 min read
SBOM

SBOM adoption in underwriting and actuarial software

Insurers price risk with software built on unvetted open-source code. Here's how SBOM underwriting software closes that blind spot.

Aug 9, 20267 min read
Software Supply Chain Security

How to conduct a software supply chain risk assessment fo...

A step-by-step guide for insurance carriers to assess software supply chain risk in vendor portfolios, from SBOM collection to continuous monitoring.

Aug 9, 20268 min read
Software Supply Chain Security

Software supply chain security for connected and autonomo...

Modern cars run 100M+ lines of code across 150 ECUs from untracked suppliers. Here's why connected vehicle software supply chain security now demands real SBOMs, not compliance checkboxes.

Aug 9, 20267 min read
Regulatory Compliance

UNECE WP.29 R155 software supply chain requirements for a...

A practical breakdown of UNECE WP.29 R155 compliance: CSMS certification, the SBOM requirement, and type approval cybersecurity rules automakers and suppliers now face.

Aug 9, 20267 min read
Vulnerability Analysis

Python tarfile extraction path traversal, the 15-year-old flaw (CVE-2007-4559)

CVE-2007-4559, a path traversal flaw in Python's tarfile module, still lurks in hundreds of thousands of repos. Here's the impact, timeline, and fix.

Aug 9, 20268 min read
SBOM

SBOM for automotive ECU firmware and embedded software

How automotive ECU firmware SBOMs help OEMs and suppliers track embedded components, manage vehicle firmware vulnerabilities, and secure OTA updates.

Aug 9, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.