Safeguard
Topic

Security

In-depth guides and analysis on security from the Safeguard engineering team.

521 articles

Security

Define Agentic: What 'Agentic' Really Means for Security

To define agentic: it describes AI systems that plan and take actions toward a goal with limited human oversight. Here is what that autonomy means for security teams.

May 19, 20265 min read
Security

Container Security: Why Reachability Analysis Changes Everything

Stop chasing phantom vulnerabilities. Learn how reachability analysis reduces CVE noise by 80% and focuses remediation on what actually matters.

Mar 1, 20263 min read
Security

CVE-2023-5752: Command Injection in pip via Mercurial Revisions

Installing a package from a Mercurial URL with a crafted revision let attackers inject hg config options. Here is how CVE-2023-5752 works and how to fix it.

Dec 8, 20255 min read
Security

eslint-plugin-unused-imports: Cleaner Code, Smaller Surface

eslint-plugin-unused-imports auto-removes dead imports that the base ESLint rule only warns about. Here is how to configure it correctly on ESLint 9.

Dec 8, 20257 min read
Security

Application Data Security: How to Protect Data Across Its Lifecycle

Application data security is the set of controls that protect data as your application collects, processes, stores, and transmits it. Here is a practical model for getting it right.

Dec 8, 20257 min read
Security

Black Duck Competitors: The Top SCA Alternatives Compared

A fair look at the main Black Duck competitors in software composition analysis — Snyk, Mend, Sonatype, Endor Labs, and others — and which fits which job.

Dec 8, 20256 min read
Security

CVE-2023-22102: The MySQL Connector/J Takeover Vulnerability

CVE-2023-22102 is a High-severity flaw in Oracle's MySQL Connector/J that can lead to connector takeover. Here is the root cause and how to remediate it.

Dec 8, 20255 min read
Security

Hacking Software: What It Is and How Defenders Use It Legally

Hacking software is the category of programs used to test and break into systems. Used with authorization, it is how security teams find their own weaknesses first.

Dec 4, 20257 min read
Security

NVD vs CVE: What's the Difference?

CVE is the list of vulnerability identifiers; the NVD is the enriched database built on top of it. They are related but run by different programs, and confusing them leads to real mistakes.

Nov 20, 20255 min read
Security

CVE Full Form Explained: What CVE Actually Stands For

The CVE full form is Common Vulnerabilities and Exposures, a public catalog of known security flaws. Here is what the term means, how the IDs work, and why it matters.

Nov 20, 20256 min read
Security

Malicious Code Detection: How to Catch Threats in Your Supply Chain

Malicious code detection is the practice of identifying deliberately harmful code in your dependencies, containers, and repositories before it runs. Here is how modern detection actually works.

Nov 19, 20256 min read
Security

How to Choose Vulnerability Assessment Solutions That Actually Reduce Risk

Most vulnerability assessment solutions generate more findings than any team can fix. The right choice depends on what you're protecting — code, dependencies, containers, or infrastructure.

Nov 19, 20257 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

Security — Supply Chain Security Blog | Safeguard