Safeguard
Tag

sca

Safeguard articles tagged "sca" — guides, analysis, and best practices for software supply chain and application security.

464 articles

SecOps

Vulnerability Scanner Software: Categories and How to Choose

Network scanners, DAST, SCA, SAST, container and cloud scanners all claim the same job. Here is what each category actually finds and how to assemble coverage without buying six consoles.

Apr 22, 20255 min read
DevSecOps

DevSecOps Tools Comparison 2025: Choosing the Right Stack

The DevSecOps tooling landscape has exploded. From SAST to SCA to SBOM management, this guide compares the major categories and helps you build a coherent security toolchain.

Apr 20, 20256 min read
Security

Peter McKay and Snyk: What His Tenure Says About Developer Security

Peter McKay led Snyk through its hypergrowth years as CEO. Here is what his tenure reveals about the developer-first security market and how to evaluate the tools it produced.

Apr 18, 20255 min read
AppSec

What Is a PHP Security Scanner and Which One Should You Use?

A PHP security scanner inspects your code and dependencies for injection flaws, insecure configuration, and known CVEs. Here is how the different tool classes work and where each fits.

Apr 17, 20257 min read
Open Source

Is react-native-svg-transformer Safe to Use? A Security Guide

react-native-svg-transformer lets you import SVG files as React components in Metro, but it runs at build time and pulls a dependency tree worth reviewing. Here's how to use it safely.

Apr 17, 20255 min read
Security

Mend Security Explained: What Mend.io Does and How It Works

A clear look at Mend security: what the platform formerly known as WhiteSource covers, how its automated remediation works, and where its strengths and gaps lie.

Apr 17, 20255 min read
AppSec

OSS Scan: How to Scan Open Source Dependencies for Vulnerabilities

An OSS scan finds known vulnerabilities in the open source packages your code depends on. Here is how the scan works, where it fits in CI, and how to act on results.

Apr 15, 20256 min read
Security

CVE-2019-10768: The AngularJS Prototype Pollution Flaw Explained

CVE-2019-10768 is a prototype pollution vulnerability in AngularJS before 1.7.9, where the merge() function can be tricked into modifying Object.prototype. Here is what it does, who it affects, and how to remediate.

Apr 15, 20255 min read
Security

DevSecOps Pipeline Example: A Secure CI/CD Workflow

A concrete DevSecOps pipeline example, stage by stage, showing where SAST, SCA, secret scanning, and DAST fit into a real CI/CD workflow.

Apr 9, 20256 min read
Open Source

Is Formik on npm Safe? A Security Review

Formik is a widely used React form library. Here is an honest look at its security history, dependency risk, and how to use it safely.

Apr 9, 20255 min read
Open Source

Is the npm express Package Safe? A Security Review

The npm express package is the most widely used Node.js web framework, and it is safe to run today if you stay on a maintained version and watch its small dependencies. Here is the security picture.

Apr 9, 20256 min read
Security

How to Choose an Enterprise Vulnerability Management Tool

What an enterprise vulnerability management tool actually needs to do, how it differs from a scanner, and the evaluation criteria that separate a program that scales from one that drowns in noise.

Apr 9, 20256 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

sca (Page 33) — Safeguard Blog