GenAI Code Assistants and Package Hallucination: 2026 Update
LLM-suggested package names that do not exist are a registered attack vector in 2026. Here is where hallucination rates sit today and how to contain them.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
LLM-suggested package names that do not exist are a registered attack vector in 2026. Here is where hallucination rates sit today and how to contain them.
A practical walkthrough of how to generate an SBOM from a container image using Syft, Trivy, and Docker Scout, plus how to keep the output trustworthy.
A practitioner's walkthrough of what the GPL license actually requires, why it matters for your dependency tree, and how it intersects with software security and compliance.
What OWASP Top 10 training actually needs to cover in 2026 now that the 2025 list has landed, plus where to find free, developer-focused courses that stick.
A working checklist to secure Docker containers, from non-root users and minimal base images to capability drops, read-only filesystems, and image scanning.
Container network security is about controlling which workloads can talk to each other and blocking the rest by default. Here is how to build that in Kubernetes and beyond.
A senior engineer's survey of AI-BOM and ML-BOM standards in 2026, from CycloneDX ML components to SPDX 3.0 AI profile, and what to actually ship.
AI chips are specialized processors built to run matrix math at scale, and the way you provision, share, and supply-chain-source them creates security risk most teams never model.
Your SBOMs come from a dozen vendors, three scanners, and two CI systems. Normalising them into one queryable graph is where SBOM programs actually succeed or fail.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.