supply-chain-security
Safeguard articles tagged "supply-chain-security" — guides, analysis, and best practices for software supply chain and application security.
100 articles
Auto-Merging Updates Fast and Reviewing What You Take Are in Conflict
Patch quickly, because exploitation begins within days. Review what you take from third parties, because a malicious version of a package you trust is the most effective supply chain attack. Auto-merge picks one and abandons the other.
A Self-Hosted Runner Is a Machine on Your Network That Runs Strangers' Code
A hosted runner is destroyed after the job. A self-hosted one persists, on your network, executing code from your repository, and if that repository accepts contributions the code is not always yours.
The Agents on Your Hosts Have More Access Than Your Application
Four agents on every production host, each running as root or with kernel privileges, each auto-updating from its vendor, each sending data outward. Your application dependencies are pinned and scanned. These are neither.
A Lockfile Is Not a Control, the Install Command Is
You pinned every dependency with an integrity hash and committed the file. None of that means the artifact you shipped contains those versions, because several install commands are allowed to resolve differently and rewrite the lockfile.
You Cannot Patch a Mobile App Quickly, So Build the Kill Switch First
Server-side remediation is a deployment. Mobile remediation is a distribution problem with a tail you do not control, and a share of your install base will still be running the vulnerable version next year.
Your Tag Manager Is a Second Deployment Pipeline With No Engineer In It
Engineering has code review, CI and branch protection. Marketing can execute arbitrary JavaScript on every page including checkout, by clicking publish. Nobody designed it that way.
The Twenty-Minute Review to Run Before You Add a Dependency
Adding a dependency takes ten seconds and commits you to trusting a stranger's code on your build machines for as long as the project lives. Six checks, the signals that should stop you, and what this deliberately does not defend against.
A Tag Is Not a Version
You deployed myapp:1.4.2 in March and myapp:1.4.2 in September. Those are not necessarily the same image. Almost every tag you rely on is a mutable pointer that someone else can move without telling you.
Your Internal Package Registry Is the Only Control That Runs Before the Code Does
Most companies run one and treat it as a cache. It is the one place in the build that can refuse a package before an install script executes, which is the only point where prevention is still possible.
The SBOM Your Customer Wants Is Not the One You Generated
An SBOM is a statement about a specific artifact. Generate it from the repository and you have an accurate document about something nobody runs, missing the base image where most of your published CVEs live.
The Dockerfile in Your Repository Is Probably Not What Builds
An urgent fix gets made on the build host, the backport never happens, and the repository copy becomes a historical document. Absent files prompt questions; stale ones answer them wrongly.
Top 12 Language Security for Software Supply Chain Security in 2026
Ranked list of the top 12 Language Security. Comprehensive evaluation of each based on security coverage, usability, and effectiveness in 2026.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.