Safeguard
Resources

Supply Chain Security, in plain English.

Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.

All (412)AI Security (786)Vulnerability Analysis (577)Security (523)DevSecOps (497)Application Security (490)Open Source Security (412)AppSec (309)Compliance (304)Industry Analysis (295)Container Security (284)Open Source (252)Best Practices (252)Cloud Security (239)Buyer's Guides (216)Software Supply Chain Security (178)Incident Analysis (139)Regulatory Compliance (138)Vulnerability Management (135)Security Guides (124)Concepts (116)Containers (100)Supply Chain Attacks (93)SBOM (76)Vulnerabilities (72)Product (69)Threat Intelligence (65)Supply Chain Security (55)Supply Chain (55)Infrastructure Security (52)Tools (50)FAQ (50)SBOM & Compliance (41)Comparisons (32)Licensing (26)Tutorials (24)Ransomware (24)Engineering (24)Guides (22)Kubernetes Security (22)SecOps (21)Vulnerability Guides (20)Regulation (20)Industry Guides (19)Case Studies (18)Compliance & Regulations (18)Emerging Technology (17)Solutions (17)Threat Research (16)Risk Management (16)Vulnerability Response (16)Tool Reviews (16)Agent Security (16)Security Concepts (15)Cryptography (15)Identity Security (15)Incident Response (15)Compliance & Frameworks (15)Industry Events (14)Security Strategy (13)Frameworks (12)Dependency Security (11)Web Security (11)Data Breach (11)Career (10)Enterprise (9)Company (9)Culture (9)Architecture (8)Strategy (8)Standards (8)Industry Trends (7)How-To Guide (7)Secure Development (7)Industry Insights (7)Dependency Management (7)Zero-Day Exploits (7)Network Security (7)Research (6)Organizational Security (6)Vendor Comparison (6)Dev Practices (6)Industry (6)Security Operations (6)Developer Security (6)Code Security (5)Breach Analysis (5)Policy (4)Cryptocurrency Security (4)Tool Comparisons (4)Offensive Security (4)Mobile Security (4)Tool Comparison (4)Product Launch (4)Analysis (3)Social Engineering (3)Build Security (3)Startup Security (3)Policy & Compliance (3)Hardware Security (3)Governance (3)Software Supply Chain (3)Healthcare Security (3)Vulnerability Research (3)Regional Security (3)Threat Actors (2)Security Culture (2)Security Architecture (2)API Security (2)Zero-Day Analysis (2)SBOM Standards (2)Security Management (2)Release (2)Industry News (2)SBOM and Compliance (2)DeFi Security (2)Tools & Techniques (1)Healthcare (1)Emerging Threats (1)Tools & Platforms (1)Architecture Security (1)Lifecycle Management (1)Privacy (1)Product Update (1)Runtime Security (1)Technical (1)Nation-State Threats (1)Credential Attacks (1)Threat Analysis (1)Incident Postmortem (1)Career Development (1)Privacy & Security (1)Threat Modeling (1)Business Continuity (1)Browser Security (1)Events (1)PKI Security (1)Language Security (1)SBOM & Standards (1)

Articles

RSS feed
Open Source Security

Auditing Spring Boot dependencies with OWASP Dependency-C...

A step-by-step spring boot dependency audit using OWASP Dependency-Check and Snyk, from Maven setup to CI automation and finding reconciliation.

Jan 21, 20267 min read
Open Source Security

OpenSSL Project Governance: Security Lessons from Heartbleed and Beyond

OpenSSL's transformation from a two-person project securing half the internet to a properly governed foundation offers a blueprint for open source security governance.

Jan 20, 20267 min read
Open Source Security

Responsible Disclosure in Open Source: The Messy Reality

Responsible disclosure sounds simple in theory. In practice, coordinating vulnerability disclosure across open source projects with no budgets, no SLAs, and no obligation to respond is an exercise in patience and diplomacy.

Jan 20, 20267 min read
Open Source Security

PyPI Malware Campaigns Surge in Q4 2022: A Roundup of the Worst Offenders

Python's package registry saw an explosion of malicious packages in late 2022, from credential stealers to reverse shells. Here's what we found.

Jan 19, 20266 min read
Open Source Security

Vulnerability Coordination Across the Open Source Ecosystem

When a vulnerability affects a library used by thousands of projects, coordinating the fix is harder than writing the patch. The coordination problem is open source security's biggest operational challenge.

Jan 18, 20267 min read
Open Source Security

Sigstore Reaches GA: Free Software Signing for Everyone

Sigstore's general availability in October 2022 made cryptographic signing accessible to every developer. Here's why this is a watershed moment.

Jan 16, 20266 min read
Open Source Security

npm Registry Security Gets Serious: 2022's Major Improvements

From mandatory MFA for top packages to enhanced login verification, npm made significant security improvements in 2022. Here's what changed.

Jan 15, 20266 min read
Open Source Security

OSS Review Toolkit (ORT): Automating License Compliance at Scale

The OSS Review Toolkit handles license scanning, vulnerability detection, and compliance policy enforcement. Here's how to put it to work.

Jan 15, 20266 min read
Open Source Security

Rust Supply Chain Security: How crates.io Stacks Up Against npm and PyPI

Rust's crates.io registry has design advantages for supply chain security, but it's not immune. Here's an honest assessment of the Rust ecosystem.

Jan 14, 20266 min read
Page 44 of 46

Stay informed

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.