<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Vulnerability on SBOM Insights</title>
    <link>https://sbom-insights.dev/tags/vulnerability/</link>
    <description>Recent content in Vulnerability on SBOM Insights</description>
    <image>
      <title>SBOM Insights</title>
      <url>https://sbom-insights.dev/apple-touch-icon.png</url>
      <link>https://sbom-insights.dev/apple-touch-icon.png</link>
    </image>
    <generator>Hugo -- 0.150.0</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 16 Feb 2026 09:30:59 -0800</lastBuildDate>
    <atom:link href="https://sbom-insights.dev/tags/vulnerability/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Stop Comparing CVE Counts: How SBOM deltas explain upstream vs hardened image security</title>
      <link>https://sbom-insights.dev/posts/upstream-vs-hardened-image-cves-why-numbers-dont-match/</link>
      <pubDate>Thu, 11 Dec 2025 23:10:15 +0530</pubDate>
      <guid>https://sbom-insights.dev/posts/upstream-vs-hardened-image-cves-why-numbers-dont-match/</guid>
      <description>Why do CVE counts differ between upstream and hardened container images? Use SBOM deltas to understand what packages changed, not just vulnerability numbers.</description>
    </item>
  </channel>
</rss>
