sca
Safeguard articles tagged "sca" — guides, analysis, and best practices for software supply chain and application security.
469 articles
What Makes a Strong Application Security Solution
An application security solution is not a single scanner but a coordinated set of controls across the software lifecycle. Here is what a real one covers.
Protestware via prompt injection: the jqwik 1.10.0 case
jqwik 1.10.0 hid a prompt injection telling AI coding agents to delete tests. Here's how it worked, why it's protestware, and how to catch it.
AI Is Forcing a New Open Source Security Model
AI coding agents now choose dependencies — and attackers are exploiting hallucinated packages and MCP backdoors that legacy SCA tools like Sonatype's were never built to catch.
Reachability Analysis as the Missing Piece of SCA
Most SCA-flagged vulnerabilities aren't exploitable. Here's why reachability analysis — not just dependency matching — is what separates real risk from noise, and where Sonatype falls short.
How Snyk detects AI/ML-specific libraries during standard...
Snyk's standard SCA treats AI/ML packages like any other dependency, while a separate AI-BOM tool adds static analysis to detect models, agents, and MCP connections.
Choosing a Software Composition Analysis Tool: A Practical Guide
A software composition analysis tool inventories your open-source dependencies and flags the vulnerable ones. Here is how it differs from static code analysis and how to pick one.
How Snyk's JetBrains plugin family supports IntelliJ, PyC...
A mechanical look at how Snyk ships one JetBrains plugin across IntelliJ, PyCharm, WebStorm, GoLand, and Rider using a shared platform and backend scan engine.
How Snyk CLI's --severity-threshold and --fail-on flags g...
How Snyk CLI severity-threshold and fail-on flags filter and gate vulnerability findings, plus exit codes and common CI/CD misconfigurations.
How the Snyk CLI's --all-projects flag discovers manifest...
A technical look at how Snyk CLI's --all-projects flag walks a repository, matches manifest files, and where directory-depth limits can leave dependencies unscanned.
Code Vulnerability Scanning Tools: How to Choose the Right One
Code vulnerability scanning tools fall into distinct categories that see different risks. Knowing which does what is the difference between coverage and false confidence.
Container Security Testing Methods, Compared
Image scanning, runtime monitoring, and configuration auditing all count as container security testing, but they catch different things at different stages — here's how to combine them.
What is SCA? Software Composition Analysis explained
SCA scans your open-source dependencies for known vulnerabilities and license risk. Here's what it checks, how it differs from SAST, and why reachability matters.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.