<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Compliance on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
    <link>https://www.msbiro.net/tags/compliance/</link>
    <description>Recent content in Compliance on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</description>
    <image>
      <title>Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
      <url>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</url>
      <link>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</link>
    </image>
    <generator>Hugo -- 0.164.0</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 24 Jun 2026 09:30:00 +0100</lastBuildDate>
    <atom:link href="https://www.msbiro.net/tags/compliance/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>In 2026 I Am Still Asked Why You Need a Hardened Container Image Catalog</title>
      <link>https://www.msbiro.net/posts/hardened-images-catalog-2026-non-negotiable/</link>
      <pubDate>Wed, 24 Jun 2026 09:30:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/hardened-images-catalog-2026-non-negotiable/</guid>
      <description>Why hardened container image catalogs are non-negotiable in 2026: the technological case, the DORA mandate, and the NIS2 obligations explained.</description>
    </item>
    <item>
      <title>GitHub Spec-Kit: Why Structured AI Development Beats Vibe Coding</title>
      <link>https://www.msbiro.net/posts/github-spec-kit-spec-driven-development/</link>
      <pubDate>Wed, 21 Jan 2026 09:23:27 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/github-spec-kit-spec-driven-development/</guid>
      <description>A DevSecOps team leader&amp;#39;s perspective on GitHub Spec-Kit, spec-driven development, and why structured AI workflows matter for compliance, auditability, and team collaboration.</description>
    </item>
    <item>
      <title>The Critical Trio: Secrets Manager, Zero-CVE Images, and CNAPP are Needed (Not Only) for DORA Compliance!</title>
      <link>https://www.msbiro.net/posts/secrets-cnapp-0cve-dora/</link>
      <pubDate>Thu, 07 Aug 2025 06:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/secrets-cnapp-0cve-dora/</guid>
      <description>Why Secrets Manager, Zero-CVE container images, and CNAPPs are essential for cybersecurity resilience and DORA compliance</description>
    </item>
  </channel>
</rss>
