<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Supply Soup on Open Source Security</title>
    <link>https://opensourcesecurity.io/tag/supply-soup/</link>
    <description>Recent content in Supply Soup on Open Source Security</description>
    <generator>Hugo -- 0.139.4</generator>
    <language>en</language>
    <lastBuildDate>Thu, 30 Jul 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://opensourcesecurity.io/tag/supply-soup/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Blog - You don&#39;t have a supply chain, you have supply soup</title>
      <link>https://opensourcesecurity.io/2026/07-supply-soup/</link>
      <pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://opensourcesecurity.io/2026/07-supply-soup/</guid>
      <description>&lt;p&gt;2026 has been a wild year. There are more vulnerabilities than anyone can count. We seem to keep talking about the number itself instead of things like how we got here or what we&amp;rsquo;re going to do about it, which is neat. The number of attacks against open source is basically an uncountable mess. Also very neat. And the cherry on top of this poop sundae is number of companies that have promised us they are going to &amp;ldquo;fix&amp;rdquo; open source, and when they use the word fix they really mean sell you a solution for a problem they mostly made up. Very cool, very cool.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
