Safeguard Q4 2025 Release Recap
A full recap of Q4 2025 at Safeguard: Griffin for Java and .NET, Eagle attestations, Lion serverless, Gold policy-aware remediation, and more.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
A full recap of Q4 2025 at Safeguard: Griffin for Java and .NET, Eagle attestations, Lion serverless, Gold policy-aware remediation, and more.
Claude Code MCP servers run with the privileges of the developer who invoked them. That makes deployment posture the entire security model.
A critical command injection flaw in the systeminformation npm package (CVE-2021-21315) let attackers run OS commands via unsanitized shell calls. Here's the full breakdown.
XML's feature richness is its security weakness. XXE, entity expansion, and XSLT injection continue to plague applications that process XML.
CVE-2022-26138 exposed a hardcoded password in the Questions for Confluence app, granting unauthenticated access to Confluence data. A preventable disaster.
Safeguard is in early-stage discussions with Tech-D Cybersecurity Ltd to explore co-selling, joint delivery, and shared services opportunities.
GCP Workload Identity Federation lets CI/CD pipelines authenticate with short-lived tokens instead of service account keys. Here's how it works and how to migrate.
As governments and enterprises demand more from open source maintainers, the community pushes back with a framework of rights. The tension between accountability and sustainability is shaping the future of open source.
CVE-2020-8203 lets attackers pollute Object.prototype via lodash's zipObjectDeep. Learn affected versions, CVSS/EPSS context, and remediation steps.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.