<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Security</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Security feed</description>
    <item>
      <title>Platform as a Product: Delivering Value While Balancing Competing Priorities</title>
      <link>https://www.infoq.com/news/2026/04/platform-product-deliver-value/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/04/platform-product-deliver-value/en/headerimage/platform-product-deliver-value-header-1775738211226.jpg"/&gt;&lt;p&gt;Software platforms must be treated as products. Success requires balancing engineering, design, usability, security, and value for internal customers and the organisation, Abby Bangser mentioned in her talk Platform as a Product. A product mindset, clear ownership, and continuous investment prevent bottlenecks, platform decay, and wasted effort, enabling scalable, sustainable value over time.&lt;/p&gt; &lt;i&gt;By Ben Linders&lt;/i&gt;</description>
      <category>Platforms</category>
      <category>Developer Experience</category>
      <category>Usability</category>
      <category>Business Value</category>
      <category>Technical Debt</category>
      <category>Platform Engineering</category>
      <category>Software Development</category>
      <category>GOTO Conference</category>
      <category>Security</category>
      <category>Culture &amp; Methods</category>
      <category>news</category>
      <pubDate>Thu, 16 Apr 2026 11:52:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/04/platform-product-deliver-value/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security</guid>
      <dc:creator>Ben Linders</dc:creator>
      <dc:date>2026-04-16T11:52:00Z</dc:date>
      <dc:identifier>/news/2026/04/platform-product-deliver-value/en</dc:identifier>
    </item>
    <item>
      <title>Presentation: Empower Your Developers: How Open Source Dependencies Risk Management Can Unlock Innovation</title>
      <link>https://www.infoq.com/presentations/open-source-dependencies/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security</link>
      <description>&lt;img src="https://res.infoq.com/presentations/open-source-dependencies/en/mediumimage/celine-pypaert-medium-1775047335370.jpeg"/&gt;&lt;p&gt;Celine Pypaert discusses the ubiquitous nature of open-source software and shares a blueprint for securing modern applications. She explains how to prioritize high-risk vulnerabilities using exploitability data, the role of Software Bill of Materials (SBOM), and the importance of bridging the gap between DevOps and Security through clear accountability and automated governance.&lt;/p&gt; &lt;i&gt;By Celine Pypaert&lt;/i&gt;</description>
      <category>QCon London 2025</category>
      <category>Open Source</category>
      <category>Risk Management</category>
      <category>Transcripts</category>
      <category>Culture &amp; Methods</category>
      <category>presentation</category>
      <pubDate>Wed, 15 Apr 2026 12:50:00 GMT</pubDate>
      <guid>https://www.infoq.com/presentations/open-source-dependencies/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security</guid>
      <dc:creator>Celine Pypaert</dc:creator>
      <dc:date>2026-04-15T12:50:00Z</dc:date>
      <dc:identifier>/presentations/open-source-dependencies/en</dc:identifier>
    </item>
    <item>
      <title>Podcast: How SBOMs and Engineering Discipline Can Help You Avoid Trivy’s Compromise</title>
      <link>https://www.infoq.com/podcasts/help-avoid-trivy-compromise/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security</link>
      <description>&lt;img src="https://res.infoq.com/podcasts/help-avoid-trivy-compromise/en/smallimage/the-infoq-podcast-logo-thumbnail-1775549272964.jpg"/&gt;&lt;p&gt;Viktor Peterson, part of the CISA task force working on SBOM blueprints and co-founder of sbomify, explores the shifting landscape of software supply chain security as the EU's Cyber Resilience Act (CRA) comes into force, a "GDPR moment" for the industry.&lt;/p&gt; &lt;i&gt;By Viktor Peterson&lt;/i&gt;</description>
      <category>The InfoQ Podcast</category>
      <category>Compliance</category>
      <category>Software Supply Chain</category>
      <category>Software Development</category>
      <category>Security</category>
      <category>DevOps</category>
      <category>Architecture &amp; Design</category>
      <category>podcast</category>
      <pubDate>Mon, 13 Apr 2026 11:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/podcasts/help-avoid-trivy-compromise/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security</guid>
      <dc:creator>Viktor Peterson</dc:creator>
      <dc:date>2026-04-13T11:00:00Z</dc:date>
      <dc:identifier>/podcasts/help-avoid-trivy-compromise/en</dc:identifier>
    </item>
    <item>
      <title>Anthropic Accidentally Exposes Claude Code Source via npm Source Map File</title>
      <link>https://www.infoq.com/news/2026/04/claude-code-source-leak/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/04/claude-code-source-leak/en/headerimage/generatedHeaderImage-1775192937059.jpg"/&gt;&lt;p&gt;Anthropic's Claude Code CLI had its full TypeScript source exposed after a source map file was accidentally included in version 2.1.88 of its npm package. The 512,000-line codebase was archived to GitHub within hours. Anthropic called it a packaging error caused by human error. The leak revealed unreleased features, internal model codenames, and multi-agent orchestration architecture.&lt;/p&gt; &lt;i&gt;By Steef-Jan Wiggers&lt;/i&gt;</description>
      <category>Anthropic</category>
      <category>Claude</category>
      <category>Security</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Tue, 07 Apr 2026 08:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/04/claude-code-source-leak/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security</guid>
      <dc:creator>Steef-Jan Wiggers</dc:creator>
      <dc:date>2026-04-07T08:00:00Z</dc:date>
      <dc:identifier>/news/2026/04/claude-code-source-leak/en</dc:identifier>
    </item>
  </channel>
</rss>
