secure-coding
Safeguard articles tagged "secure-coding" — guides, analysis, and best practices for software supply chain and application security.
188 articles
How to Run JavaScript Code: Methods and Security Notes
A practical guide to how to run JavaScript code in the browser, with Node.js, and from the command line, plus the security traps that turn a convenient runner into a liability.
LDAP Injection Attacks: How They Work and How to Prevent Them
LDAP injection lets an attacker manipulate directory-service queries by inserting special filter characters into user input, often bypassing authentication entirely — here's how the attack works and how to stop it.
PHP Application Security: A Practical Guide to Locking Down Your Code
PHP application security comes down to a handful of high-impact controls. Here is how to handle injection, sessions, uploads, and dependencies without the theory.
Code Error Finder Tools: Catching Security Bugs Early
A code error finder is any tool that surfaces bugs before they ship — and the ones that matter most for security catch the errors that turn into vulnerabilities.
Pickling in Python: A Security Guide
Pickling in Python serializes objects to bytes, but unpickling untrusted data can run arbitrary code. Here is how the risk works and how to defend against it.
"The Code Is Correct!" and Other Myths That Hide Security Bugs
Passing tests and a clean review tell you the code is correct, but correctness and security are not the same thing. Here is where the gap lives.
Code Review Best Practices for Java: A Security-First Guide
Security-focused code review best practices for Java teams: what to look for, how to structure reviews, and the recurring bug classes that slip past compilers.
OWASP Top 10 Vulnerabilities 2023: A Retrospective That Still Applies
There was no new web OWASP Top 10 in 2023 — but the OWASP Top 10 vulnerabilities 2023 story is really about the 2021 web list holding firm and the API Security Top 10 getting a major refresh.
How a Code Error Solver Helps You Fix Bugs Without Adding Risk
A code error solver turns cryptic stack traces into fixes, but the tempting one-line patch it hands you can quietly introduce a vulnerability. Here is how to use one safely.
What Is a Code Injection Attack and How Do You Prevent It?
A code injection attack tricks an application into running attacker-supplied code as if it were trusted. Here is how the class works and how to shut it down.
Java Stream Sum: How to Add Numbers Safely in Java
A practical look at computing a Java stream sum correctly, from IntStream.sum() to reduce(), plus the overflow and null pitfalls that turn a simple total into a bug.
SAST Testing Tools: How to Choose and Use Them Effectively
A practitioner's guide to SAST testing tools: what static analysis actually catches, where it falls short, and how to wire it into a pipeline without drowning developers in noise.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.