Semgrep SCA: How Reachability Changes Dependency Scanning
What Semgrep SCA (Supply Chain) does, how its reachability analysis cuts alert noise, where it fits, and how to run it in CI.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
What Semgrep SCA (Supply Chain) does, how its reachability analysis cuts alert noise, where it fits, and how to run it in CI.
A clear XSS example shows how unescaped user input becomes executable script in a victim's browser, and why output encoding and CSP are the fixes that hold.
Choosing among DAST vendors hinges on how well the scanner authenticates, crawls modern apps and APIs, and fits into CI without turning into a manual chore.
A DAST automated test probes your running application for vulnerabilities the way an attacker would, on every build. Here is how it works and the benefits of wiring it into CI.
A SQL injection detected alert means a scanner or WAF found input reaching your database as executable code. Here is how to confirm it, triage it, and fix the root cause.
A URL scanner checks a web address for danger before you visit or ship it — but 'URL scanner' covers two very different tools. Here is how each works and which one solves your problem.
Security in PHP improved enormously once frameworks took over escaping, CSRF, and query building. The remaining incidents live in the gaps where developers step outside those rails.
A code scanning tool automatically inspects your source and dependencies for vulnerabilities. Here is how the main types differ and how to wire one into CI without drowning in noise.
Java code security has a specific set of recurring failure modes — deserialization, XXE, dependency sprawl — this checklist covers the ones worth checking on every review.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.