supply-chain
Safeguard articles tagged "supply-chain" — guides, analysis, and best practices for software supply chain and application security.
859 articles
Is @vitejs/plugin-react Safe? A Security Review
@vitejs/plugin-react is a build-time dev dependency, so its security story is mostly about supply chain trust and keeping it current rather than runtime exploits.
@ctrl/tinycolor and the 40-Package npm Wave of September 2025
@ctrl/tinycolor versions 4.1.1 and 4.1.2 shipped a credential-stealing payload that propagated to 40+ packages with 2 million combined weekly downloads in under 24 hours.
Docker Scanners: Comparing the Image-Scanning Options
A docker scanner has to check three separate layers — base OS packages, application dependencies, and the Dockerfile itself — and most tools are genuinely strong at only one or two.
The HIPAA Security Rule Update and Your Supply Chain
HHS's December 2024 NPRM rewrites the HIPAA Security Rule with explicit software supply chain, SBOM, and business associate controls set to take effect in 2025 and 2026.
AI Chip Security: What Accelerators Mean for Your Threat Model
An AI chip is specialized hardware for running machine learning workloads, and it brings its own security concerns from supply chain to firmware. Here is what matters.
SBOM Examples: What a Real Software Bill of Materials Looks Like
Concrete SBOM examples in both SPDX and CycloneDX, showing what fields actually go in a software bill of materials and how the two formats differ in practice.
Malware Meaning: What It Is and How It Spreads
The meaning of malware is simple — any software written to harm, exploit, or gain unauthorized access — but the categories and delivery methods are worth knowing.
npm copyfiles: A Security Review and Safe Usage Guide
copyfiles is a tiny cross-platform file-copy CLI that a lot of build scripts rely on. Here is its security profile and how to use the npm copyfiles package carefully.
CNCF Supply Chain Security Best Practices v2: What Changed
CNCF TAG Security shipped the v2 Supply Chain Security paper in 2025, mainstreaming SBOMs, signed attestations, and zero-trust workload identity. We walk through the practical guidance.
Salesloft Drift OAuth Breach: 700+ Salesforce Tenants Compromised
UNC6395 stole Salesloft Drift OAuth tokens to exfiltrate Salesforce data from more than 700 organisations including Cloudflare, Zscaler, and Palo Alto Networks in August 2025.
CNAPPs in 2025: What Cloud-Native Application Protection Platforms Actually Protect
CNAPP has become the dominant category in cloud security. But the label covers wildly different capabilities. A clear-eyed look at what CNAPPs do, where they fall short, and how supply chain security fits in.
jest-environment-jsdom: Setup, Gotchas, and Supply Chain Notes
Setting up npm jest-environment-jsdom correctly, why it stopped shipping with Jest, and what its jsdom dependency tree means for your test toolchain's security.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.