<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://kolega.dev</loc>
<lastmod>2026-04-03T09:43:33.803Z</lastmod>
<changefreq>weekly</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://kolega.dev/security-wins</loc>
<lastmod>2026-04-03T09:43:33.803Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://kolega.dev/advisories</loc>
<lastmod>2026-04-03T09:43:33.803Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://kolega.dev/blog</loc>
<lastmod>2026-04-03T09:43:33.803Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://kolega.dev/security-wins/openclaw-security-assessment</loc>
<lastmod>2026-02-14T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/security-wins/cloudreve-security-assessment</loc>
<lastmod>2026-01-13T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/security-wins/phase-security-assessment</loc>
<lastmod>2026-01-13T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/security-wins/agenta-security-assessment</loc>
<lastmod>2026-01-13T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/security-wins/vllm-security-assessment</loc>
<lastmod>2026-01-12T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/security-wins/qdrant-security-assessment</loc>
<lastmod>2026-01-08T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/security-wins/weaviate-security-assessment</loc>
<lastmod>2026-01-07T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/security-wins/langfuse-security-assessment</loc>
<lastmod>2025-12-26T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/security-wins/nocodb-security-assessment</loc>
<lastmod>2025-12-22T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/advisories/agentic-ai-framework-security-openclaw-as-a-case-study-for-industry-wide</loc>
<lastmod>2026-02-25T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/advisories/react2shell-vulnerability-emergency</loc>
<lastmod>2025-12-13T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/the-8-most-common-vulnerabilities-in-ai-generated-code</loc>
<lastmod>2026-03-31T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/your-security-scanner-was-the-weapon-the-teampcp-supply-chain-attack</loc>
<lastmod>2026-03-27T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/y-combinator-just-celebrated-building-a-generation-of-insecure-startups</loc>
<lastmod>2026-03-21T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/why-we-built-our-own-security-benchmark</loc>
<lastmod>2026-03-17T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/you-cant-secure-openclaw-you-can-secure-yours</loc>
<lastmod>2026-03-07T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/kolega-dev-owasp-benchmark-results</loc>
<lastmod>2026-02-26T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/we-tested-snyks-own-demo-repo-their-scanner-found-nothing</loc>
<lastmod>2026-02-24T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/control-drift-why-your-soc-2-compliance-cant-keep-up-with-ai-written-code</loc>
<lastmod>2026-02-14T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/how-we-got-a-90-fix-rate-on-open-source-security-reports</loc>
<lastmod>2026-02-10T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/vibe-coding-is-a-security-disaster-that-is-about-to-happen</loc>
<lastmod>2026-02-06T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/the-87-problem-why-traditional-security-tools-generate-noise</loc>
<lastmod>2026-02-04T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/the-sql-injection-that-sast-didnt-find</loc>
<lastmod>2026-02-03T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/the-hidden-risks-of-modern-code-security-patterns-tools-keep-missing</loc>
<lastmod>2026-01-23T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/why-most-security-alerts-are-noise-and-how-to-fix-it</loc>
<lastmod>2026-01-20T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/why-we-found-225-security-flaws-in-45-open-source-projects-that-sast-missed</loc>
<lastmod>2026-01-14T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://kolega.dev/blog/the-7-best-sast-solutions-for-2026-why-scanning-the-old-way-isnt-enoug</loc>
<lastmod>2026-01-13T00:00:00.000Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.7</priority>
</url>
</urlset>
