<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>quodeq blog</title>
    <link>https://quodeq.ai/blog/</link>
    <description>Updates, thoughts, and technical writing from the quodeq project.</description>
    <language>en</language>
    <atom:link href="https://quodeq.ai/blog/feed.xml" rel="self" type="application/rss+xml" />

    <item>
      <title>Your Dependencies Are Someone Else's Attack Surface</title>
      <link>https://quodeq.ai/blog/supply-chain-attack-surface/</link>
      <guid>https://quodeq.ai/blog/supply-chain-attack-surface/</guid>
      <pubDate>Mon, 14 Apr 2026 00:00:00 +0000</pubDate>
      <description>Supply chain attacks have escalated sharply in fifteen months. Shai-Hulud, Axios, TeamPCP, and what you can do about it.</description>
    </item>

    <item>
      <title>Project Glasswing Has a Blind Spot. It's You.</title>
      <link>https://quodeq.ai/blog/glasswing-blind-spot/</link>
      <guid>https://quodeq.ai/blog/glasswing-blind-spot/</guid>
      <pubDate>Sun, 13 Apr 2026 00:00:00 +0000</pubDate>
      <description>Glasswing gave 50 organizations access to AI-powered vulnerability discovery. What about the other 33 million developers?</description>
    </item>

    <item>
      <title>Introducing Quodeq</title>
      <link>https://quodeq.ai/blog/introducing-quodeq/</link>
      <guid>https://quodeq.ai/blog/introducing-quodeq/</guid>
      <pubDate>Sat, 01 Mar 2026 00:00:00 +0000</pubDate>
      <description>Why we built an AI-powered code quality compass, and what makes it different from static analysis.</description>
    </item>

  </channel>
</rss>
