Is the exceljs npm Package Safe? A Security Review
The exceljs npm package is a maintained, popular library for reading and writing Excel files, and it is a reasonable choice, but parsing untrusted spreadsheets carries real risk. Here is the review.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
The exceljs npm package is a maintained, popular library for reading and writing Excel files, and it is a reasonable choice, but parsing untrusted spreadsheets carries real risk. Here is the review.
An honest guide to the best SBOM tools in 2026 — from open-source generators like Syft and Trivy to full SBOM management and AIBOM platforms — with clear guidance on which to use for generation, analysis, and compliance.
An authenticated stack buffer overflow in Cisco IOS and IOS XE SNMP is being exploited in the wild. We dissect the bug, the patch, and the detection signal.
An honest, side-by-side guide to the best software supply chain security platforms in 2026 — what each tool is genuinely good at, who it fits, and how to choose between zero-CVE, SCA, reachability, and CNAPP approaches.
OpenAI's Daybreak and Anthropic's Mythos both bet that frontier models can find and fix vulnerabilities at scale. The discovery race is real — but the bottleneck, the cost curve, and the winning strategy all point the same direction: be model-agnostic.
Checkmarx API Security discovers your real API footprint — including shadow and zombie endpoints — and correlates static and dynamic findings. Here's how it fits an AppSec program.
The spring-web Maven artifact pulls a lot of transitive weight and has been at the center of high-profile RCE bugs. Here is what to watch and how to keep it patched.
A defender's synthesis of the first half of 2026 — self-propagating package worms, the agentic-AI access-control problem, edge-appliance zero-days, and a healthcare ransomware surge — and what to prioritize next.
CVE-2023-46589 lets an attacker smuggle HTTP requests past a reverse proxy by abusing malformed trailer headers in Apache Tomcat. Here is how it works and which versions to run.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.