GitLab CI/CD Security Configuration
Hardening GitLab CI/CD pipelines with protected variables, secure runners, and built-in security scanning.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
Hardening GitLab CI/CD pipelines with protected variables, secure runners, and built-in security scanning.
Software attestation is moving from academic concept to practical requirement. Here's how to implement it in your build pipelines today.
Chaos engineering principles applied to the software supply chain reveal hidden dependencies, single points of failure, and degradation paths that only surface under stress.
The 3CX supply chain attack exposed critical gaps in how software vendors protect their build pipelines. Here are the concrete lessons.
Step-by-step guide to enabling SAST, DAST, dependency scanning, and container scanning in GitLab CI pipelines.
Brakeman understands Rails conventions and catches security issues that generic scanners miss. Here is how to use it effectively.
Git credentials are the keys to your source code. Here is how organizations should manage them to prevent unauthorized access and credential theft.
Securing Spinnaker's multi-cloud deployment pipelines with authentication, authorization, pipeline constraints, and artifact verification.
gosec is the standard security linter for Go. Here is what it catches, what it misses, and how to integrate it effectively into your workflow.
Weekly insights on software supply chain security, delivered to your inbox.