Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (309)AI Security (786)Vulnerability Analysis (577)Security (523)DevSecOps (497)Application Security (490)Open Source Security (412)AppSec (309)Compliance (304)Industry Analysis (295)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (135)Security Guides (124)Concepts (116)Containers (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Product (69)Threat Intelligence (65)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)Tools (50)FAQ (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Engineering (24)Tutorials (24)Ransomware (24)Kubernetes Security (22)Guides (22)SecOps (21)Regulation (20)Vulnerability Guides (20)Industry Guides (19)Case Studies (18)Compliance & Regulations (18)Solutions (17)Emerging Technology (17)Agent Security (16)Vulnerability Response (16)Threat Research (16)Risk Management (16)Tool Reviews (16)Cryptography (15)Compliance & Frameworks (15)Security Concepts (15)Identity Security (15)Incident Response (15)Industry Events (14)Security Strategy (13)Frameworks (12)Data Breach (11)Dependency Security (11)Web Security (11)Career (10)Company (9)Culture (9)Enterprise (9)Standards (8)Strategy (8)Architecture (8)Secure Development (7)Industry Insights (7)Industry Trends (7)How-To Guide (7)Zero-Day Exploits (7)Network Security (7)Dependency Management (7)Industry (6)Vendor Comparison (6)Dev Practices (6)Security Operations (6)Research (6)Organizational Security (6)Developer Security (6)Breach Analysis (5)Code Security (5)Product Launch (4)Policy (4)Cryptocurrency Security (4)Tool Comparison (4)Mobile Security (4)Offensive Security (4)Tool Comparisons (4)Build Security (3)Healthcare Security (3)Governance (3)Social Engineering (3)Vulnerability Research (3)Regional Security (3)Policy & Compliance (3)SBOM Standards (3)Software Supply Chain (3)Analysis (3)Startup Security (3)Hardware Security (3)Zero-Day Analysis (2)Industry News (2)Release (2)SBOM and Compliance (2)Security Management (2)Threat Actors (2)API Security (2)Security Architecture (2)Security Culture (2)DeFi Security (2)Incident Postmortem (1)Technical (1)Product Update (1)Healthcare (1)Language Security (1)Emerging Threats (1)Privacy (1)Events (1)Lifecycle Management (1)Career Development (1)Tools & Platforms (1)Threat Modeling (1)Browser Security (1)Threat Analysis (1)Business Continuity (1)Runtime Security (1)Credential Attacks (1)PKI Security (1)Architecture Security (1)Nation-State Threats (1)Tools & Techniques (1)Privacy & Security (1)

Articles

RSS feed
AppSec

Open Source SAST Tools Worth Evaluating

A rundown of the open source SAST tools engineering teams actually use in production, and where each one runs out of road.

Apr 26, 20265 min read
AppSec

Code Injection in Python: How It Happens and How to Prevent It

Code injection python vulnerabilities almost always trace back to eval, exec, or a template engine handed untrusted input; here is how the attack works and how to close it off.

Apr 26, 20266 min read
AppSec

org.apache.tomcat.embed: Embedded Tomcat Versions and Vulnerabilities

org.apache.tomcat.embed ships inside almost every Spring Boot jar, and its CVEs follow it there. Here is how to find your real embedded Tomcat version and patch it.

Apr 25, 20268 min read
AppSec

Static Code Analysis in Cyber Security: What It Actually Does

Static code analysis in cyber security means scanning source code without running it to catch injection flaws, hardcoded secrets, and unsafe patterns before they ship — here's what it catches and what it misses.

Apr 25, 20265 min read
AppSec

Website Vulnerability Scanners: How They Work and What They Miss

How a website vulnerability scanner crawls, fuzzes, and fingerprints your app, plus the whole classes of flaws it structurally cannot find on its own.

Apr 25, 20266 min read
AppSec

SAST Testing: How Static Analysis Finds Bugs Before They Run

A SAST test analyzes source code without executing it to find vulnerabilities like injection and hardcoded secrets. Here is how it works and where it fits.

Apr 25, 20266 min read
AppSec

Web Application Penetration Testing: What to Expect

A real web application penetration test follows a scoped, multi-phase process — here's what happens before, during, and after the engagement so the report doesn't surprise you.

Apr 24, 20265 min read
AppSec

IAST Meaning: What Interactive Application Security Testing Does

IAST instruments a running application from the inside, watching real execution to confirm vulnerabilities with far fewer false positives than static scanning.

Apr 24, 20266 min read
AppSec

CVSS 4.0 Release Date, Changes, and Adoption Status

The CVSS 4.0 release date was November 1, 2023 — here is what changed from v3.1, how the new metric groups work, and where real-world adoption stands.

Apr 23, 20267 min read
Page 19 of 35

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Blog — appsec (Page 19) | Safeguard — Software Supply Chain Security Insights