Shopify's Supply Chain Security Program
How Shopify built a supply chain security program that protects millions of merchants while maintaining the development velocity that e-commerce demands.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
How Shopify built a supply chain security program that protects millions of merchants while maintaining the development velocity that e-commerce demands.
CVE-2024-21762 gave attackers pre-auth RCE on FortiGate SSL VPN. We trace the exploitation patterns, scanner behavior, and who got hit first.
gVisor intercepts syscalls in userspace and implements a minimal kernel in Go. It is a genuinely different approach, with genuinely different trade-offs.
New York's DFS cybersecurity regulation sets a high bar for financial institutions. Here's how the 2023 amendments affect software supply chain practices.
Governments worldwide are mandating supply chain incident disclosure. Here is what organizations need to know about notification requirements across major jurisdictions.
A deep comparison of Semgrep and CodeQL for static application security testing, covering rule writing, performance, language support, and practical deployment considerations.
XXE attacks exploit XML parser features that most applications never need. Here is how to disable them across every major language and framework.
A hands-on tutorial for blocking unsigned container images at the Kubernetes admission layer using Cosign, Sigstore policy-controller, and keyless verification.
Securing your .NET supply chain with NuGet package signing, lock files, and vulnerability scanning.
Weekly insights on software supply chain security, delivered to your inbox.