sca
Safeguard articles tagged "sca" — guides, analysis, and best practices for software supply chain and application security.
469 articles
Security Testing in the Software Development Lifecycle
Security testing for software development only works when it's distributed across the SDLC, not bolted on as a single pre-release gate — here's where each test type actually belongs.
Dependabot Alternatives in 2026: A Buyer Rubric
A buyer rubric for evaluating Dependabot alternatives in 2026, covering update strategy, ecosystem coverage, reachability, and operational realities.
Is the Busboy npm Package Safe? A Security Review
The busboy npm package parses multipart form data in Node.js. Here is its current security status, the dicer history that once bit it, and how to use it safely.
Zip Slip: archive extraction path traversal explained
Zip Slip lets malicious archives write files outside their extraction folder via ../ paths — how it works, real CVEs, and how to detect and fix it.
An SCA Tools List That Matches How You Actually Ship
A candid SCA tools list for teams that need dependency and license scanning wired into CI, covering open-source scanners and commercial platforms and how to tell them apart.
Semgrep Supply Chain: April 2026 Update Reviewed
Semgrep's April 2026 release added dedicated advisory pages, dependency path data in SBOM exports, a Guardian Supply Chain hook, and Maven/Gradle scanning without lockfiles.
PHP Code Check: A Security Guide
A PHP code check should catch injection, unsafe deserialization, and vulnerable Composer packages before they ship. Here is a layered approach that fits a normal PHP workflow.
FOSSA vs Snyk SCA Comparison 2026
Two SCA platforms with very different roots: FOSSA from license compliance, Snyk from vulnerability scanning. Which one fits which buyer profile in 2026?
What Is Checkmarx One? A Practical Look at the AppSec Platform
Checkmarx One is Checkmarx's cloud application security platform, bundling SAST, SCA, IaC, and more into a single console. Here is what it covers and where it fits.
MIT-Lizenz: Was sie erlaubt und was kommerzielle Nutzung bedeutet
Die MIT-Lizenz ist eine der freizuegigsten Open-Source-Lizenzen und erlaubt auch die kommerzielle Nutzung. Wir erklaeren Pflichten, Grenzen und Risiken.
Open source license management and scanning
33% of codebases ship components with no discernible license, and Aikido's manifest-based scanning still misses vendored code and stale registry metadata. Here's what real license compliance requires.
Transitive dependency vulnerabilities explained
A vulnerability three layers deep in your dependency graph is still your problem. Here's how transitive flaws like Log4Shell hide, spread, and get fixed.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.