<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Vamsi</title><description>Product Security Engineer in Germany focused on application security, AI/ML security, DevSecOps, and threat modeling.</description><link>https://thedevappsecguy.github.io/vamsi/</link><item><title>Supply Chain Security in CI/CD</title><link>https://thedevappsecguy.github.io/vamsi/notes/ci-cd-detection/</link><guid isPermaLink="true">https://thedevappsecguy.github.io/vamsi/notes/ci-cd-detection/</guid><description>Supply chain security in CI/CD needs more than prevention. The critical gap is detecting when workflows, credentials, runners, or dependencies are turned into attack paths.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate></item><item><title>sec-skills</title><link>https://thedevappsecguy.github.io/vamsi/notes/sec-skills/</link><guid isPermaLink="true">https://thedevappsecguy.github.io/vamsi/notes/sec-skills/</guid><description>Use this when you want one shared set of skills for recurring agentic coding workflows across tools.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate></item><item><title>skill-scanner</title><link>https://thedevappsecguy.github.io/vamsi/notes/skill-scanner/</link><guid isPermaLink="true">https://thedevappsecguy.github.io/vamsi/notes/skill-scanner/</guid><description>Use this when you want to review skills in any agentic workflow before they enter local workflows, CI, or other automated flows.</description><pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate></item></channel></rss>