<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Syft on Ortelius</title>
    <link>/tags/syft/</link>
    <description>Recent content in Syft on Ortelius</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Thu, 13 Aug 2026 15:15:14 -0600</lastBuildDate>
    <atom:link href="/tags/syft/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>From SBOM Collection to Continuous Vulnerability Management with Ortelius</title>
      <link>/blog/2026/08/12/from-sbom-collection-to-continuous-vulnerability-management-with-ortelius/</link>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <guid>/blog/2026/08/12/from-sbom-collection-to-continuous-vulnerability-management-with-ortelius/</guid>
      <description>&lt;div class=&#34;col-center&#34;&gt;&#xA;&lt;img src=&#34;/images/Ortelius-for-SBOM-Defense.png&#34; alt=&#34;Ortelius for SBOM Defense&#34; height=&#34;360px&#34; width=&#34;545px&#34; /&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;&lt;/p&gt;&#xA;&lt;p&gt;Modern software organizations are producing more software, more containers, and more releases than security teams can reasonably track by hand. Applications are assembled from hundreds or thousands of open-source packages and distributed across different CI/CD pipelines, registries, Kubernetes environments, cloud platforms, and development teams. The challenge is no longer simply creating an SBOM. The challenge is collecting SBOMs consistently, keeping them associated with the correct software versions running in production, and then using that information to determine when newly discovered vulnerabilities affect software that has already been released.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
