Is the DOMPurify npm Package Safe? CVEs and Secure Usage
DOMPurify (npm) is the right tool for sanitizing HTML against XSS, and it is safe when you keep it patched - but it has had real bypass CVEs, so version discipline matters.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
DOMPurify (npm) is the right tool for sanitizing HTML against XSS, and it is safe when you keep it patched - but it has had real bypass CVEs, so version discipline matters.
A practical walkthrough to create an npm package in TypeScript, plus the supply-chain hardening steps most tutorials skip: provenance, dependency hygiene, and safe publishing.
The DevOps performance metrics worth tracking are the four DORA metrics plus a handful of security signals that reveal whether speed is coming at the cost of risk.
On May 11, 2026, attackers chained a pull_request_target abuse, cache poisoning, and OIDC token theft to publish 84 malicious @tanstack npm versions from TanStack's own trusted pipeline. It is the first npm compromise to carry valid SLSA provenance.
Palo Alto disclosed CVE-2026-0265 on May 13, 2026, a cryptographic-signature-verification flaw in Cloud Authentication Service that bypasses PAN-OS authentication. Researchers claim live GlobalProtect portal bypasses. Full analysis.
On 14 May 2026, three malicious node-ipc versions (9.1.6, 9.2.3, 12.0.1) shipped an 80 KB credential-stealing IIFE appended after module.exports in the CJS bundle — no install scripts, harvesting 90+ secret categories from a library with 10M+ weekly downloads.
Microsoft's May 14, 2026 research found AI frameworks shipping Helm charts that expose web UIs on internet-facing LoadBalancers with no authentication and cluster-admin service accounts. Mage AI on port 6789 was the headline, but it was far from alone.
Malware code is any code written to run without the owner's informed consent and against their interest. Understanding its patterns is what makes it detectable.
A realistic product security engineer job description: the actual responsibilities, the skills that matter, how the role differs from AppSec, and what the salary looks like.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.