Safeguard
Tag

extensions

Safeguard articles tagged "extensions" — guides, analysis, and best practices for software supply chain and application security.

6 articles

Cloud Security

Azure Functions extensions as a supply chain entry point in 2026

Binding extensions and isolated worker SDK packages run with the function's managed identity. Here is how to evaluate and gate them in 2026.

May 12, 20267 min read
Application Security

VS Code Extensions and Supply Chain Risk in 2026

VS Code extensions run with full editor privileges and broad filesystem access. A look at the real attacks, the marketplace's blind spots, and how to harden the workstation.

Feb 20, 20266 min read
Open Source Security

Python Cython Extensions and the Supply Chain

Cython-built Python extensions ship as platform-specific binaries with a build toolchain behind them. That introduces supply chain surface most teams have not mapped.

Feb 14, 20257 min read
Security

CVE-2024-0333: The Chrome Extensions Data Validation Flaw Explained

CVE-2024-0333 is an insufficient data validation bug in Chrome's Extensions component that let a network attacker push a malicious extension. Here is what it is and how to stay patched.

Jan 25, 20255 min read
Developer Security

VS Code Extension Marketplace Security: The IDE Supply Chain

VS Code extensions run with the same privileges as your editor — which means full access to your source code, terminal, and credentials. The marketplace security model does not prevent malicious extensions.

Oct 18, 20225 min read
Infrastructure Security

Database Extensions as Supply Chain Risk: The Overlooked Attack Surface

PostgreSQL extensions, MySQL plugins, and database add-ons run with database-level privileges. A compromised extension has direct access to your data. Most organizations never audit them.

Sep 28, 20225 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

extensions — Safeguard Blog