<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://gastropod.io/</loc>
  </url>
  <url>
    <loc>https://gastropod.io/product</loc>
  </url>
  <url>
    <loc>https://gastropod.io/federation</loc>
  </url>
  <url>
    <loc>https://gastropod.io/pricing</loc>
  </url>
  <url>
    <loc>https://gastropod.io/security</loc>
  </url>
  <url>
    <loc>https://gastropod.io/demo</loc>
  </url>
  <url>
    <loc>https://gastropod.io/terms</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news</loc>
  </url>
  <url>
    <loc>https://gastropod.io/compare/artifactory</loc>
  </url>
  <url>
    <loc>https://gastropod.io/compare/nexus</loc>
  </url>
  <url>
    <loc>https://gastropod.io/compare/cloudsmith</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/npm</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/go</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/pypi</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/docker</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/maven</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/alpine</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/apt</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/rpm</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/nuget</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/helm</loc>
  </url>
  <url>
    <loc>https://gastropod.io/ecosystems/rubygems</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/16-typosquatted-rubygems-packages-delivered-a-windows-infostealer-through-the-native-build-proces</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/fourteen-npm-packages-working-as-intended-except-that-pesky-linux-backdoor-feature-that-was-snuck-in</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/geoserver-s-sql-injection-zero-day-was-being-scanned-for-within-hours-of-the-irresponsible-disclosure</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/nearly-800-npm-packages-ai-generated-names-one-shared-backdoor-inside-wel1dropper</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/one-endpoint-full-admin-inside-the-metabase-bug-cisa-says-to-patch-asap</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/14-090-vulnerabilities-in-two-months-and-99-4-of-them-have-no-cve</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/77-counterfeit-open-vsx-extensions-with-a-config-file-that-keeps-installing-the</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/the-keyv-worm-published-releases-that-had-no-commit-behind-them</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/apostrophecms-s-critical-auth-bypass</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/no-login-required-teamcity-s-critical-rce-and-your-build</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/pypi-and-github-are-racing-against-time-for-package-poisoning</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/no-patch-for-fastjson-1-x-cve-2026-16723-is-an-inventory-problem-to-solve</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/langflow-just-got-its-fifth-cve-added-to-cisa-s-exploited-list-this-year</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/borrowed-compute-how-ten-packagist-libraries-turned-github-actions-into-an-attack-botnet</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/what-the-openai-hugging-face-breach-says-about-sbom-blind-spots</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/fakegit-7-600-repos-14-million-downloads-and-an-ai-agent-reading-the-attacker-s-readme</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/vvitevenom-trouble-with-trusting-a-scope-name</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/eleven-bytes-no-cve-the-openssl-hollowbyte-flaw-that-scanners-miss</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/sleepergem-dormant-rubygems-accounts-reactivated-to-deliver-a-persistent-backdoor</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/when-your-own-ci-pipeline-publishes-the-backdoor-inside-the-injective-sdk-wallet-key-theft</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/asyncapi-npm-supply-chain-attack-a-valid-signature-isn-t-the-same-as-a-safe-package</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/the-npm-package-that-only-turned-evil-when-you-used-it</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/braintree-net-nuget-typosquat</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/laravel-lang-tag-rewrite-supply-chain-attack</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/paysafe-skrill-neteller-fake-sdk-typosquat-campaign</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/he-jscrambler-npm-compromise-is-a-textbook-case-of-we-don-t-know-where-that-package-went</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/inside-the-asyncapi-miasma-attack-when-the-pipeline-itself-becomes-the-attacker</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/gastropod-a-superior-alternative-to-jfrog-or-nexus</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/gastropod-is-live</loc>
  </url>
  <url>
    <loc>https://gastropod.io/news/introducing-gastropod</loc>
  </url>
</urlset>
