Safeguard
Tag

sca

Safeguard articles tagged "sca" — guides, analysis, and best practices for software supply chain and application security.

100 articles

Vulnerability Management

A Clean Scan Usually Means the Scanner Did Not Look

Analysed your code and found nothing, or failed to analyse your code and therefore found nothing. Most tools report both as success. Seven reasons coverage collapses, and the canary dependency that proves a scan still works.

Sep 17, 20266 min read
Infrastructure Security

What Actually Breaks When You Scan Without Internet Access

Every dependency scanner is a program that looks things up. The six things it needs a network for, the four operating models people all call air-gapped, and the questions to ask before a proof of concept.

Sep 17, 20266 min read
Buyer's Guides

Evaluate a Security Scanner in Three Weeks, Not Six Months

A standard bake-off measures detection on code both tools have seen, weights forty rows equally, and tests week one of a week-fifty problem. Six questions with real variance, and how to run them against your incumbent too.

Sep 17, 20266 min read
Vulnerability Management

Five Places Reachability Analysis Says Unreachable and Is Wrong

Reachability is the best noise filter in dependency scanning and its failure mode is silence, not an error. The five cases where the call graph is incomplete, and what to do about each.

Sep 17, 20266 min read
Vulnerability Analysis

The Version String Is Not the Vulnerability

A CVE that needs Windows, a dev server, and a reachable port is not exploitable because a version matched. Cataloguing what each advisory actually requires turns a lockfile diff into an argument.

Aug 14, 20265 min read
Software Supply Chain Security

Nobody Is Exploiting Your Dependencies. They Are Logging Into Them.

keyv, Mastra, Nx, AsyncAPI, jscrambler. Five of 2026's largest supply chain incidents, and not one involved a software vulnerability. The exploited weakness every time was a maintainer account.

Aug 8, 20266 min read
AppSec

How to Read a Security Scanning Report Without Drowning in Noise

A security scanning report lists what a scanner found across your code, dependencies, and infrastructure. Here's how to read one, prioritize it, and act on what matters.

Jul 29, 20266 min read
Open Source Security

Python's .pth Files Are a Code Execution Primitive, and Attackers Noticed

The June 2026 PyPI worm wave used a *-setup.pth file to execute at interpreter startup — before your code, before your imports, on every single python invocation. It then fetched the Bun JavaScript runtime to run its payload. If your supply chain model stops at setup.py, it has a hole in it.

Jul 28, 20267 min read
Open Source Security

npm v12 Disabled Install Scripts. Attackers Adapted in Three Days.

On 8 July 2026 npm v12 shipped with install scripts off by default — closing what GitHub called the ecosystem's largest code-execution surface. By 11 July, the jscrambler payload was executing on import instead. A study in why one-vector mitigations buy days, not years.

Jul 28, 20266 min read
Open Source Security

The Jscrambler npm Compromise Went After Your AI Coding Assistant's Credentials

On 11 July 2026, five versions of the jscrambler package plus its webpack, gulp, grunt and metro plugins shipped malicious native binaries. The payload targeted crypto wallets and the credential stores of Claude Desktop, Cursor and Windsurf — and later versions fired on import, not install, defeating --ignore-scripts.

Jul 28, 20266 min read
AppSec

Code Security Scan: How to Scan Your Code for Vulnerabilities

A code security scan analyzes your source and its dependencies for security flaws before they ship. Here is how the main scan types work, what tools to use, and how to wire scanning into CI without drowning in noise.

Jul 25, 20267 min read
Security

Malicious Code Detection: How to Catch Threats in Your Supply Chain

Malicious code detection is the practice of identifying deliberately harmful code in your dependencies, containers, and repositories before it runs. Here is how modern detection actually works.

Jul 23, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.