<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
  xmlns:xhtml="http://www.w3.org/1999/xhtml">
  <url>
    <loc>https://quaerens.dev/categories/best-practices/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/ci/cd/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/compliance/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/compliance-frameworks/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/container-security/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/dependency-management/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/devops/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/how-supply-chain-security-reduces-time-to-market/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/kubernetes/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/nist-ssdf/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/sbom/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/security/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/slsa/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/software-supply-chain-security/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/supply-chain-attacks/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/vulnerability-scanning/</loc>
    <lastmod>2025-12-25T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/risk-assessment/</loc>
    <lastmod>2025-12-24T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/real-cost-supply-chain-vulnerabilities-calculating-risk/</loc>
    <lastmod>2025-12-24T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/vulnerability-management/</loc>
    <lastmod>2025-12-24T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/case-studies/</loc>
    <lastmod>2025-12-23T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/devops/</loc>
    <lastmod>2025-12-23T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/industry-trends/</loc>
    <lastmod>2025-12-23T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/shift-left/</loc>
    <lastmod>2025-12-23T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/solarwinds/</loc>
    <lastmod>2025-12-23T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/why-traditional-application-security-isnt-enough-anymore/</loc>
    <lastmod>2025-12-23T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/ai/</loc>
    <lastmod>2025-12-22T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/ai-and-machine-learning-in-supply-chain-security-opportunities-and-risks/</loc>
    <lastmod>2025-12-22T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/ci/cd-security/</loc>
    <lastmod>2025-12-22T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/machine-learning/</loc>
    <lastmod>2025-12-22T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/software-supply-chain-security/</loc>
    <lastmod>2025-12-22T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/ai-security/</loc>
    <lastmod>2025-12-21T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/artifact-signing/</loc>
    <lastmod>2025-12-21T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/iac/</loc>
    <lastmod>2025-12-21T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/provenance/</loc>
    <lastmod>2025-12-21T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/ssdf/</loc>
    <lastmod>2025-12-21T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/future-software-supply-chain-security-2025-predictions/</loc>
    <lastmod>2025-12-21T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/zero-trust/</loc>
    <lastmod>2025-12-21T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/creating-a-software-security-incident-response-plan-for-supply-chain-attacks/</loc>
    <lastmod>2025-12-20T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/incident-response/</loc>
    <lastmod>2025-12-20T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/nist/</loc>
    <lastmod>2025-12-20T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/github-actions/</loc>
    <lastmod>2025-12-19T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/security-automation/</loc>
    <lastmod>2025-12-19T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/setting-up-automated-vulnerability-scanning-in-github-actions/</loc>
    <lastmod>2025-12-19T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/trivy/</loc>
    <lastmod>2025-12-19T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/cis-controls/</loc>
    <lastmod>2025-12-18T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/how-to-conduct-a-software-supply-chain-risk-assessment-in-5-steps/</loc>
    <lastmod>2025-12-18T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/build-vs-buy-develop-in-house-supply-chain-security-solutions/</loc>
    <lastmod>2025-12-17T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/software-supply-chain-security-tools-comparison-features-pricing-use-cases/</loc>
    <lastmod>2025-12-16T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/license-compliance/</loc>
    <lastmod>2025-12-15T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/open-source-vs-commercial-software-composition-analysis-tools/</loc>
    <lastmod>2025-12-15T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/sca/</loc>
    <lastmod>2025-12-15T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/transitive-dependencies-explained-the-hidden-risk-in-your-codebase/</loc>
    <lastmod>2025-12-14T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/cosign/</loc>
    <lastmod>2025-12-13T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/policy-enforcement/</loc>
    <lastmod>2025-12-13T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/provenance-attestation/</loc>
    <lastmod>2025-12-13T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/provenance-attestation-verifying-software-authenticity-at-scale/</loc>
    <lastmod>2025-12-13T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/how-to-implement-zero-trust-architecture-in-your-development-environment/</loc>
    <lastmod>2025-12-12T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/identity-management/</loc>
    <lastmod>2025-12-12T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/policy-as-code/</loc>
    <lastmod>2025-12-12T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/runtime-protection/</loc>
    <lastmod>2025-12-11T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/vulnerability-scanning-vs-runtime-protection-whats-the-difference/</loc>
    <lastmod>2025-12-11T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/cis-benchmark/</loc>
    <lastmod>2025-12-10T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/dependency-confusion/</loc>
    <lastmod>2025-12-10T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/devsecops/</loc>
    <lastmod>2025-12-10T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/supply-chain-attacks-in-2025-real-world-case-studies-and-lessons-learned/</loc>
    <lastmod>2025-12-10T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/financial-services-software-security-meeting-compliance-while-staying-agile/</loc>
    <lastmod>2025-12-09T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/pci-dss/</loc>
    <lastmod>2025-12-09T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/fda/</loc>
    <lastmod>2025-12-08T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/healthcare-software-security-protecting-medical-device-supply-chains/</loc>
    <lastmod>2025-12-08T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/medical-devices/</loc>
    <lastmod>2025-12-08T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/gdpr/</loc>
    <lastmod>2025-12-07T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/gdpr-and-software-dependencies-managing-third-party-data-risks/</loc>
    <lastmod>2025-12-07T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/privacy-reviews/</loc>
    <lastmod>2025-12-07T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/third-party-risk/</loc>
    <lastmod>2025-12-07T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/soc-2/</loc>
    <lastmod>2025-12-06T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/soc-2-and-software-supply-chain-security-what-you-need-to-know/</loc>
    <lastmod>2025-12-06T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/supply-chain-security-requirements-preparing-for-executive-order-14028/</loc>
    <lastmod>2025-12-05T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/gitops/</loc>
    <lastmod>2025-12-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/gitops-security-protecting-your-infrastructure-as-code-workflows/</loc>
    <lastmod>2025-12-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/infrastructure-as-code/</loc>
    <lastmod>2025-12-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/admission-control/</loc>
    <lastmod>2025-12-03T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/container-security-best-practices-for-kubernetes-deployments/</loc>
    <lastmod>2025-12-03T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/least-privilege/</loc>
    <lastmod>2025-12-03T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/network-policies/</loc>
    <lastmod>2025-12-03T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/runtime-monitoring/</loc>
    <lastmod>2025-12-03T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/automation/</loc>
    <lastmod>2025-12-02T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/devsecops-implementation-guide-shifting-security-left-in-your-organization/</loc>
    <lastmod>2025-12-02T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/security-scanning/</loc>
    <lastmod>2025-12-02T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/pipeline-hardening/</loc>
    <lastmod>2025-12-01T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/secrets-management/</loc>
    <lastmod>2025-12-01T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/12/securing-your-ci-cd-pipeline-a-step-by-step-checklist/</loc>
    <lastmod>2025-12-01T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/11/dependency-management-how-to-secure-third-party-components-in-your-applications/</loc>
    <lastmod>2025-11-30T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/11/slsa-framework-explained-achieving-supply-chain-security-compliance/</loc>
    <lastmod>2025-11-29T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/compliance/</loc>
    <lastmod>2025-11-28T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/cyclonedx/</loc>
    <lastmod>2025-11-28T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/11/sbom-best-practices-how-to-generate-and-manage-software-bills-of-materials/</loc>
    <lastmod>2025-11-28T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/spdx/</loc>
    <lastmod>2025-11-28T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/11/5-critical-vulnerabilities-hiding-in-your-software-supply-chain-and-how-to-find-them/</loc>
    <lastmod>2025-11-27T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/11/software-supply-chain-maturity-assessment-guide-2025/</loc>
    <lastmod>2025-11-26T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/ci-cd/</loc>
    <lastmod>2025-11-18T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/observability/</loc>
    <lastmod>2025-11-18T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/perspicax/</loc>
    <lastmod>2025-11-18T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/products/perspicax/</loc>
    <lastmod>2025-11-18T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/pipelines/</loc>
    <lastmod>2025-11-18T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/products/</loc>
    <lastmod>2025-11-18T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/products/</loc>
    <lastmod>2025-11-18T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/build-provenance/</loc>
    <lastmod>2025-10-24T10:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/devsecops/</loc>
    <lastmod>2025-10-24T10:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/security-framework/</loc>
    <lastmod>2025-10-24T10:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/blog/2025/10/slsa-framework-complete-guide/</loc>
    <lastmod>2025-10-24T10:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/software-artifacts/</loc>
    <lastmod>2025-10-24T10:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/software-security/</loc>
    <lastmod>2025-10-24T10:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/software-supply-chain/</loc>
    <lastmod>2025-10-24T10:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/supply-chain-security/</loc>
    <lastmod>2025-10-24T10:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/probatus/</loc>
    <lastmod>2025-10-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/products/probatus/</loc>
    <lastmod>2025-10-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/maturity-assessment/</loc>
    <lastmod>2024-10-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/owasp-scm/</loc>
    <lastmod>2024-10-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/categories/services/</loc>
    <lastmod>2024-10-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/services/</loc>
    <lastmod>2024-10-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/tags/software-supply-chain/</loc>
    <lastmod>2024-10-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/services/software-supply-chain-maturity-assessment/</loc>
    <lastmod>2024-10-04T00:00:00+00:00</lastmod>
  </url><url>
    <loc>https://quaerens.dev/authors/</loc>
  </url>
</urlset>
