sbom
Safeguard articles tagged "sbom" — guides, analysis, and best practices for software supply chain and application security.
100 articles
A Lockfile Is Not a Control, the Install Command Is
You pinned every dependency with an integrity hash and committed the file. None of that means the artifact you shipped contains those versions, because several install commands are allowed to resolve differently and rewrite the lockfile.
What to Tell Customers When a Dependency You Ship Is Compromised
The first message has to go out before the investigation finishes. What to say at each stage, the order that establishes scope, and why historical lockfiles turn a week of archaeology into a query.
The SBOM Your Customer Wants Is Not the One You Generated
An SBOM is a statement about a specific artifact. Generate it from the repository and you have an accurate document about something nobody runs, missing the base image where most of your published CVEs live.
The Seven Artifacts Every Enterprise Security Review Asks For
The customer security review is the most expensive gate in enterprise software sales and the most predictable. The same seven artifacts get requested in roughly the same order, and preparing them early turns nine weeks into two.
Patch Lag Explains the Old Breaches. It Does Not Explain the New Ones.
Reviewing two decades of major incidents, the ones that defined early security were patch-adoption failures. A growing share of recent ones had no patch to apply, because the compromise was in the distribution chain itself. These need different defences.
66,000 CVEs: The Year Enumeration Stopped Being a Strategy
2026 is forecast to close near 66,000 CVEs, driven partly by AI-assisted discovery. At that volume reading the list is not a job anyone can do — and most programmes are still built around reading it.
SBOM adoption in underwriting and actuarial software
Insurers price risk with software built on unvetted open-source code. Here's how SBOM underwriting software closes that blind spot.
How to conduct a software supply chain risk assessment fo...
A step-by-step guide for insurance carriers to assess software supply chain risk in vendor portfolios, from SBOM collection to continuous monitoring.
Software supply chain security for connected and autonomo...
Modern cars run 100M+ lines of code across 150 ECUs from untracked suppliers. Here's why connected vehicle software supply chain security now demands real SBOMs, not compliance checkboxes.
UNECE WP.29 R155 software supply chain requirements for a...
A practical breakdown of UNECE WP.29 R155 compliance: CSMS certification, the SBOM requirement, and type approval cybersecurity rules automakers and suppliers now face.
Python tarfile extraction path traversal, the 15-year-old flaw (CVE-2007-4559)
CVE-2007-4559, a path traversal flaw in Python's tarfile module, still lurks in hundreds of thousands of repos. Here's the impact, timeline, and fix.
SBOM for automotive ECU firmware and embedded software
How automotive ECU firmware SBOMs help OEMs and suppliers track embedded components, manage vehicle firmware vulnerabilities, and secure OTA updates.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.