Safeguard
Tag

sca

Safeguard articles tagged "sca" — guides, analysis, and best practices for software supply chain and application security.

469 articles

DevSecOps

Snyk and GitHub Actions: How to Wire Up CI Scanning

How to set up Snyk in GitHub Actions the right way — the official actions, storing your token, uploading SARIF to code scanning, and gating pull requests.

Jun 23, 20266 min read
Security

snyk.io: What It Is, What It Costs, and How It Fits Your Stack

A straight look at snyk.io: what the platform scans, how its 2025 pricing tiers and test caps work, and where it fits alongside other security tooling.

Jun 21, 20266 min read
AppSec

Code Scan Tools: How They Work and What to Use

A practical breakdown of code scan tool categories — SAST, SCA, secrets, and DAST — how each works, and how to choose and combine them without alert fatigue.

Jun 20, 20266 min read
Security

PyPI Security News: How to Track and Respond to Python Package Threats

Keeping up with PyPI security news is now part of the job for any Python team. Here is how to follow the threats that matter and act before a malicious package reaches production.

Jun 20, 20266 min read
Containers

Scanning Docker Images for Vulnerabilities: How To

Knowing how to scan Docker images for vulnerabilities before they ship is the difference between catching a known CVE in CI and finding it in an incident report.

Jun 19, 20265 min read
AI Security

Software Supply Chain Attack News Today: What to Watch For

Software supply chain attack news today keeps pointing at the same target: open source package registries like npm and PyPI. Here is what the recent wave of attacks looks like and how to defend against it.

Jun 18, 20267 min read
Supply Chain

SCA vs Static Code Analysis: The Real Difference

Software composition analysis and static code analysis get lumped together constantly, but they read entirely different things and catch entirely different bugs.

Jun 18, 20266 min read
Security

Snyk in Cybersecurity: Where It Fits in a Modern AppSec Program

How Snyk fits into a cybersecurity program: what its developer-first SCA, SAST, container, and IaC tools cover, and what they leave for other controls.

Jun 18, 20265 min read
Open Source

@angular-builders/custom-webpack: Extending Angular Builds Without Ejecting

The @angular-builders/custom-webpack package lets you merge custom webpack config into Angular CLI builds. Here is how it works and how to use it without adding risk.

Jun 17, 20265 min read
Security

Snyk Status: How to Check if Snyk Is Down and What to Do About It

The Snyk status page at status.snyk.io tells you whether the platform, its scanners, and integrations are healthy. Here is how to read it and how to keep a Snyk outage from breaking your pipeline.

Jun 16, 20266 min read
AppSec

App Vulnerability Scanner: How It Works and What to Use

An app vulnerability scanner automatically probes your application for known flaws and misconfigurations. Here is how the main types work and how to pick the right one.

Jun 16, 20266 min read
Security

Black Duck and Synopsys: What the Spinoff Means for SCA

Black Duck is now an independent company after splitting from Synopsys in 2024. Here is what changed, and what it means if you rely on it for SCA.

Jun 15, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

sca (Page 14) — Safeguard Blog