<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://gastropod.io/</loc>
  </url>
  <url>
    <loc>https://gastropod.io/product</loc>
  </url>
  <url>
    <loc>https://gastropod.io/federation</loc>
  </url>
  <url>
    <loc>https://gastropod.io/pricing</loc>
  </url>
  <url>
    <loc>https://gastropod.io/security</loc>
  </url>
  <url>
    <loc>https://gastropod.io/demo</loc>
  </url>
  <url>
    <loc>https://gastropod.io/terms</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/77-counterfeit-open-vsx-extensions-with-a-config-file-that-keeps-installing-the</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/the-keyv-worm-published-releases-that-had-no-commit-behind-them</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/apostrophecms-s-critical-auth-bypass</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/no-login-required-teamcity-s-critical-rce-and-your-build</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/pypi-and-github-are-racing-against-time-for-package-poisoning</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/no-patch-for-fastjson-1-x-cve-2026-16723-is-an-inventory-problem-to-solve</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/langflow-just-got-its-fifth-cve-added-to-cisa-s-exploited-list-this-year</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/borrowed-compute-how-ten-packagist-libraries-turned-github-actions-into-an-attack-botnet</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/what-the-openai-hugging-face-breach-says-about-sbom-blind-spots</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/fakegit-7-600-repos-14-million-downloads-and-an-ai-agent-reading-the-attacker-s-readme</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/vvitevenom-trouble-with-trusting-a-scope-name</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/eleven-bytes-no-cve-the-openssl-hollowbyte-flaw-that-scanners-miss</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/sleepergem-dormant-rubygems-accounts-reactivated-to-deliver-a-persistent-backdoor</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/when-your-own-ci-pipeline-publishes-the-backdoor-inside-the-injective-sdk-wallet-key-theft</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/asyncapi-npm-supply-chain-attack-a-valid-signature-isn-t-the-same-as-a-safe-package</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/the-npm-package-that-only-turned-evil-when-you-used-it</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/braintree-net-nuget-typosquat</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/laravel-lang-tag-rewrite-supply-chain-attack</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/paysafe-skrill-neteller-fake-sdk-typosquat-campaign</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/he-jscrambler-npm-compromise-is-a-textbook-case-of-we-don-t-know-where-that-package-went</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/inside-the-asyncapi-miasma-attack-when-the-pipeline-itself-becomes-the-attacker</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/gastropod-a-superior-alternative-to-jfrog-or-nexus</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/gastropod-is-live</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/introducing-gastropod</loc>
  </url>
</urlset>
