sca
Safeguard articles tagged "sca" — guides, analysis, and best practices for software supply chain and application security.
100 articles
A Clean Scan Usually Means the Scanner Did Not Look
Analysed your code and found nothing, or failed to analyse your code and therefore found nothing. Most tools report both as success. Seven reasons coverage collapses, and the canary dependency that proves a scan still works.
What Actually Breaks When You Scan Without Internet Access
Every dependency scanner is a program that looks things up. The six things it needs a network for, the four operating models people all call air-gapped, and the questions to ask before a proof of concept.
Evaluate a Security Scanner in Three Weeks, Not Six Months
A standard bake-off measures detection on code both tools have seen, weights forty rows equally, and tests week one of a week-fifty problem. Six questions with real variance, and how to run them against your incumbent too.
Five Places Reachability Analysis Says Unreachable and Is Wrong
Reachability is the best noise filter in dependency scanning and its failure mode is silence, not an error. The five cases where the call graph is incomplete, and what to do about each.
The Version String Is Not the Vulnerability
A CVE that needs Windows, a dev server, and a reachable port is not exploitable because a version matched. Cataloguing what each advisory actually requires turns a lockfile diff into an argument.
Nobody Is Exploiting Your Dependencies. They Are Logging Into Them.
keyv, Mastra, Nx, AsyncAPI, jscrambler. Five of 2026's largest supply chain incidents, and not one involved a software vulnerability. The exploited weakness every time was a maintainer account.
How to Read a Security Scanning Report Without Drowning in Noise
A security scanning report lists what a scanner found across your code, dependencies, and infrastructure. Here's how to read one, prioritize it, and act on what matters.
Python's .pth Files Are a Code Execution Primitive, and Attackers Noticed
The June 2026 PyPI worm wave used a *-setup.pth file to execute at interpreter startup — before your code, before your imports, on every single python invocation. It then fetched the Bun JavaScript runtime to run its payload. If your supply chain model stops at setup.py, it has a hole in it.
npm v12 Disabled Install Scripts. Attackers Adapted in Three Days.
On 8 July 2026 npm v12 shipped with install scripts off by default — closing what GitHub called the ecosystem's largest code-execution surface. By 11 July, the jscrambler payload was executing on import instead. A study in why one-vector mitigations buy days, not years.
The Jscrambler npm Compromise Went After Your AI Coding Assistant's Credentials
On 11 July 2026, five versions of the jscrambler package plus its webpack, gulp, grunt and metro plugins shipped malicious native binaries. The payload targeted crypto wallets and the credential stores of Claude Desktop, Cursor and Windsurf — and later versions fired on import, not install, defeating --ignore-scripts.
Code Security Scan: How to Scan Your Code for Vulnerabilities
A code security scan analyzes your source and its dependencies for security flaws before they ship. Here is how the main scan types work, what tools to use, and how to wire scanning into CI without drowning in noise.
Malicious Code Detection: How to Catch Threats in Your Supply Chain
Malicious code detection is the practice of identifying deliberately harmful code in your dependencies, containers, and repositories before it runs. Here is how modern detection actually works.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.