Safeguard
Tag

supply-chain

Safeguard articles tagged "supply-chain" — guides, analysis, and best practices for software supply chain and application security.

859 articles

Open Source

Is @vitejs/plugin-react Safe? A Security Review

@vitejs/plugin-react is a build-time dev dependency, so its security story is mostly about supply chain trust and keeping it current rather than runtime exploits.

Jun 22, 20265 min read
Supply Chain

@ctrl/tinycolor and the 40-Package npm Wave of September 2025

@ctrl/tinycolor versions 4.1.1 and 4.1.2 shipped a credential-stealing payload that propagated to 40+ packages with 2 million combined weekly downloads in under 24 hours.

Jun 20, 20265 min read
Containers

Docker Scanners: Comparing the Image-Scanning Options

A docker scanner has to check three separate layers — base OS packages, application dependencies, and the Dockerfile itself — and most tools are genuinely strong at only one or two.

Jun 19, 20265 min read
Regulatory Compliance

The HIPAA Security Rule Update and Your Supply Chain

HHS's December 2024 NPRM rewrites the HIPAA Security Rule with explicit software supply chain, SBOM, and business associate controls set to take effect in 2025 and 2026.

Jun 18, 20265 min read
AI Security

AI Chip Security: What Accelerators Mean for Your Threat Model

An AI chip is specialized hardware for running machine learning workloads, and it brings its own security concerns from supply chain to firmware. Here is what matters.

Jun 18, 20266 min read
Compliance

SBOM Examples: What a Real Software Bill of Materials Looks Like

Concrete SBOM examples in both SPDX and CycloneDX, showing what fields actually go in a software bill of materials and how the two formats differ in practice.

Jun 16, 20265 min read
Security

Malware Meaning: What It Is and How It Spreads

The meaning of malware is simple — any software written to harm, exploit, or gain unauthorized access — but the categories and delivery methods are worth knowing.

Jun 16, 20265 min read
Open Source

npm copyfiles: A Security Review and Safe Usage Guide

copyfiles is a tiny cross-platform file-copy CLI that a lot of build scripts rely on. Here is its security profile and how to use the npm copyfiles package carefully.

Jun 15, 20265 min read
Industry

CNCF Supply Chain Security Best Practices v2: What Changed

CNCF TAG Security shipped the v2 Supply Chain Security paper in 2025, mainstreaming SBOMs, signed attestations, and zero-trust workload identity. We walk through the practical guidance.

Jun 15, 20267 min read
Incident Analysis

Salesloft Drift OAuth Breach: 700+ Salesforce Tenants Compromised

UNC6395 stole Salesloft Drift OAuth tokens to exfiltrate Salesforce data from more than 700 organisations including Cloudflare, Zscaler, and Palo Alto Networks in August 2025.

Jun 14, 20266 min read
Cloud Security

CNAPPs in 2025: What Cloud-Native Application Protection Platforms Actually Protect

CNAPP has become the dominant category in cloud security. But the label covers wildly different capabilities. A clear-eyed look at what CNAPPs do, where they fall short, and how supply chain security fits in.

Jun 13, 20267 min read
Open Source

jest-environment-jsdom: Setup, Gotchas, and Supply Chain Notes

Setting up npm jest-environment-jsdom correctly, why it stopped shipping with Jest, and what its jsdom dependency tree means for your test toolchain's security.

Jun 8, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

supply-chain (Page 6) — Safeguard Blog