sca
Safeguard articles tagged "sca" — guides, analysis, and best practices for software supply chain and application security.
468 articles
Nobody Is Exploiting Your Dependencies. They Are Logging Into Them.
keyv, Mastra, Nx, AsyncAPI, jscrambler. Five of 2026's largest supply chain incidents, and not one involved a software vulnerability. The exploited weakness every time was a maintainer account.
How to Read a Security Scanning Report Without Drowning in Noise
A security scanning report lists what a scanner found across your code, dependencies, and infrastructure. Here's how to read one, prioritize it, and act on what matters.
Python's .pth Files Are a Code Execution Primitive, and Attackers Noticed
The June 2026 PyPI worm wave used a *-setup.pth file to execute at interpreter startup — before your code, before your imports, on every single python invocation. It then fetched the Bun JavaScript runtime to run its payload. If your supply chain model stops at setup.py, it has a hole in it.
npm v12 Disabled Install Scripts. Attackers Adapted in Three Days.
On 8 July 2026 npm v12 shipped with install scripts off by default — closing what GitHub called the ecosystem's largest code-execution surface. By 11 July, the jscrambler payload was executing on import instead. A study in why one-vector mitigations buy days, not years.
The Jscrambler npm Compromise Went After Your AI Coding Assistant's Credentials
On 11 July 2026, five versions of the jscrambler package plus its webpack, gulp, grunt and metro plugins shipped malicious native binaries. The payload targeted crypto wallets and the credential stores of Claude Desktop, Cursor and Windsurf — and later versions fired on import, not install, defeating --ignore-scripts.
Code Security Scan: How to Scan Your Code for Vulnerabilities
A code security scan analyzes your source and its dependencies for security flaws before they ship. Here is how the main scan types work, what tools to use, and how to wire scanning into CI without drowning in noise.
Malicious Code Detection: How to Catch Threats in Your Supply Chain
Malicious code detection is the practice of identifying deliberately harmful code in your dependencies, containers, and repositories before it runs. Here is how modern detection actually works.
How to Choose Vulnerability Assessment Solutions That Actually Reduce Risk
Most vulnerability assessment solutions generate more findings than any team can fix. The right choice depends on what you're protecting — code, dependencies, containers, or infrastructure.
Best SBOM management and analysis platforms
A practical buyer's guide to SBOM management platforms in 2026 -- evaluation criteria plus an honest look at six real vendors and where each one falls short.
Finding vulnerable code hidden inside shaded and uber JARs
JFrog found 65% of Log4Shell-affected artifacts embedded raw .class files instead of a jar — invisible to scanners that only read pom.xml metadata.
Jackson ObjectMapper and the gadget-chain trap: safe polymorphic deserialization
One FasterXML fix in 2017 spawned nearly 30 follow-up CVEs. Here's how Jackson's polymorphic typing enables RCE, and how to configure ObjectMapper safely.
Secure SDLC: A Practical Guide to Embedding Security Gates in Every Phase
NIST finalized the Secure Software Development Framework in February 2022, yet most teams still bolt security on at release. Here's where the gates actually belong.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.