Path Traversal in Dependency Installation: Writing Files Where They Should Not Go
Package archives can contain path traversal sequences that write files outside the expected directory. Most developers never check for this.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
Package archives can contain path traversal sequences that write files outside the expected directory. Most developers never check for this.
Running pip install can execute arbitrary code on your machine before you ever import the package. Here is how install hooks create risk.
C and C++ libraries still power critical infrastructure everywhere. Their memory safety issues are your problem whether you write C or not.
Lockfile injection is a subtle supply chain attack where malicious changes to package-lock.json redirect dependency resolution to attacker-controlled packages. Here is how it works and how to detect it.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.