Safeguard
Tag

sca

Safeguard articles tagged "sca" — guides, analysis, and best practices for software supply chain and application security.

464 articles

Security

Synk Artinya: What Snyk Means and Does

Synk artinya apa? A plain explanation of what Snyk is, what the tool does, how its pricing works, and where it fits in a security toolchain.

Jun 18, 20255 min read
AppSec

PDFKit v0.8.6 Command Injection (CVE-2022-25765): Detection and Fix

The pdfkit v0.8.6 exploit is CVE-2022-25765, a command injection in the Ruby pdfkit gem where an unsanitized URL reaches the shell. How it works conceptually, how to detect it, and the fix.

Jun 17, 20256 min read
Governance

Writing an Open Source Software Policy

An open source software policy is what turns ad-hoc dependency choices into a governed, auditable process — here's what to actually put in one.

Jun 17, 20254 min read
Supply Chain

Open Source Code Scanning: Tools and Workflow

Open source code scanning tools can cover most of a small team's needs for free, but the workflow around them — what runs where, and who reviews the output — matters more than which tool you pick.

Jun 17, 20255 min read
Security

Lodash 4.17.21 Vulnerabilities: What the 'Safe' Version Still Misses

Lodash 4.17.21 was the release that fixed the famous prototype pollution and command injection bugs. Here is what it patched and why it is no longer the final word.

Jun 16, 20255 min read
Security

What Makes a Good Open Source Security Platform?

An open source security platform has to cover the whole dependency lifecycle, not just print CVEs. Here is what the category actually includes and how to evaluate one for your stack.

Jun 16, 20256 min read
Containers

Docker Image Security Scan: How to Scan Images for Vulnerabilities

A Docker image security scan inspects the layers of an image for known-vulnerable packages before you ship it. Here are the tools, commands, and the workflow that keeps scanning useful.

Jun 11, 20256 min read
Security

How Much Does Black Duck Cost? A Guide to Black Duck Pricing

Black Duck pricing is quote-only and negotiated per codebase and team size. Here is what drives the cost, the ballpark figures teams report, and how to evaluate whether it fits your budget.

Jun 11, 20255 min read
Security

Snyk Ltd: What the Company Builds and How Its Pricing Works

A factual overview of Snyk Ltd, the developer-security company: what its products do, how its plans are priced, and what to weigh when evaluating it.

Jun 11, 20255 min read
AppSec

Secure Code Scanning: What It Is and How to Do It Right

Secure code scanning finds vulnerabilities in source and dependencies before they ship. Here is how SAST, SCA, and secret scanning fit together in CI.

Jun 11, 20255 min read
AppSec

Application Security Vulnerability Management: A Working Workflow

A concrete workflow for application security vulnerability management, from scan to fix to verified close, that survives contact with a real release calendar.

Jun 11, 20255 min read
Security

Snyk REST API: How the Versioned Endpoints Actually Work

The Snyk REST API uses date-based versioning and a Bearer token, which trips up first-time integrators. Here is how it differs from the old v1 API and how to make your first call.

Jun 9, 20255 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

sca (Page 30) — Safeguard Blog