sca
Safeguard articles tagged "sca" — guides, analysis, and best practices for software supply chain and application security.
464 articles
Synk Artinya: What Snyk Means and Does
Synk artinya apa? A plain explanation of what Snyk is, what the tool does, how its pricing works, and where it fits in a security toolchain.
PDFKit v0.8.6 Command Injection (CVE-2022-25765): Detection and Fix
The pdfkit v0.8.6 exploit is CVE-2022-25765, a command injection in the Ruby pdfkit gem where an unsanitized URL reaches the shell. How it works conceptually, how to detect it, and the fix.
Writing an Open Source Software Policy
An open source software policy is what turns ad-hoc dependency choices into a governed, auditable process — here's what to actually put in one.
Open Source Code Scanning: Tools and Workflow
Open source code scanning tools can cover most of a small team's needs for free, but the workflow around them — what runs where, and who reviews the output — matters more than which tool you pick.
Lodash 4.17.21 Vulnerabilities: What the 'Safe' Version Still Misses
Lodash 4.17.21 was the release that fixed the famous prototype pollution and command injection bugs. Here is what it patched and why it is no longer the final word.
What Makes a Good Open Source Security Platform?
An open source security platform has to cover the whole dependency lifecycle, not just print CVEs. Here is what the category actually includes and how to evaluate one for your stack.
Docker Image Security Scan: How to Scan Images for Vulnerabilities
A Docker image security scan inspects the layers of an image for known-vulnerable packages before you ship it. Here are the tools, commands, and the workflow that keeps scanning useful.
How Much Does Black Duck Cost? A Guide to Black Duck Pricing
Black Duck pricing is quote-only and negotiated per codebase and team size. Here is what drives the cost, the ballpark figures teams report, and how to evaluate whether it fits your budget.
Snyk Ltd: What the Company Builds and How Its Pricing Works
A factual overview of Snyk Ltd, the developer-security company: what its products do, how its plans are priced, and what to weigh when evaluating it.
Secure Code Scanning: What It Is and How to Do It Right
Secure code scanning finds vulnerabilities in source and dependencies before they ship. Here is how SAST, SCA, and secret scanning fit together in CI.
Application Security Vulnerability Management: A Working Workflow
A concrete workflow for application security vulnerability management, from scan to fix to verified close, that survives contact with a real release calendar.
Snyk REST API: How the Versioned Endpoints Actually Work
The Snyk REST API uses date-based versioning and a Bearer token, which trips up first-time integrators. Here is how it differs from the old v1 API and how to make your first call.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.