supply-chain-security
Safeguard articles tagged "supply-chain-security" — guides, analysis, and best practices for software supply chain and application security.
1106 articles
Practical steps to secure third-party WebAssembly plugins...
A step-by-step guide to securing third-party WebAssembly plugins in production: sandboxing, capability restriction, resource limits, provenance checks, and runtime monitoring.
CVE-2023-5752: Command Injection in pip via Mercurial Revisions
Installing a package from a Mercurial URL with a crafted revision let attackers inject hg config options. Here is how CVE-2023-5752 works and how to fix it.
@angular-devkit/build-angular: A Security Guide to the Angular Build Package
@angular-devkit/build-angular is the build toolchain behind the Angular CLI. Most of its security risk is transitive, coming from the build and dev-server dependencies it pulls in.
CVE-2023-22102: The MySQL Connector/J Takeover Vulnerability
CVE-2023-22102 is a High-severity flaw in Oracle's MySQL Connector/J that can lead to connector takeover. Here is the root cause and how to remediate it.
Black Duck Competitors: The Top SCA Alternatives Compared
A fair look at the main Black Duck competitors in software composition analysis — Snyk, Mend, Sonatype, Endor Labs, and others — and which fits which job.
The Secure Software Development Lifecycle in 2025: What Actually Changed
A practical look at how SSDLC practices evolved in 2025, what worked, what failed, and why most organizations are still getting the basics wrong.
How AI safety benchmarks and evaluations measure model risk
A concrete look at how AI safety benchmark evaluation, LLM safety scorecards, and capability testing actually measure model risk in 2026 — and where they fall short.
How indirect prompt injection hides malicious instruction...
How attackers hide malicious instructions inside webpages, documents, and retrieved content to hijack AI systems — and why RAG pipelines are especially exposed.
Typosquatting in open source package registries explained
Typosquatting hides malware behind a one-character package name typo. Learn how it works, real incidents, and how to detect it before your build runs.
How to detect malicious npm packages
Real npm supply chain attacks — event-stream, ua-parser-js, node-ipc, and the 2025 chalk/debug breach — show how to spot and stop malicious packages.
Subresource integrity bypass explained
SRI hashes can't stop what happens before the hash is made. How polyfill.io, British Airways, and event-stream exposed real gaps in browser integrity checks.
How to build an AI-specific incident response playbook
A step-by-step guide to building an AI incident response plan — covering scoping, escalation, detection, containment, and post-incident review for LLM and agent failures.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.