<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>chs.us — Carl Sampson</title><link>https://chs.us/</link><description/><language>en-us</language><managingEditor>carl.sampson@gmail.com (Carl Sampson)</managingEditor><webMaster>carl.sampson@gmail.com (Carl Sampson)</webMaster><lastBuildDate>Fri, 10 Apr 2026 17:05:31 -0400</lastBuildDate><atom:link href="https://chs.us/tags/dependency-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Software Supply Chain Security Guide</title><link>https://chs.us/guides/supply-chain/</link><pubDate>Fri, 10 Apr 2026 00:00:00 +0000</pubDate><author>carl.sampson@gmail.com (Carl Sampson)</author><guid>https://chs.us/guides/supply-chain/</guid><description>A defender&amp;#39;s reference for software supply chain risks — threat model across the SDLC, package-registry attack patterns, CI/CD hardening, artifact provenance and signing, SBOMs, dependency scanning, case studies, and a checklist. Compiled from 29 research sources.</description><category>Security-Guides</category><category>Supply-Chain-Security</category><category>Devops-Security</category><category>Dependency-Security</category><category>Ci-Cd-Security</category></item></channel></rss>