<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>OtterSight Blog</title><description>Software Composition Analysis — SCA, SBOM, CVE, EUVD insights for developers</description><link>https://ottersight.com/</link><language>en</language><item><title>The Axios Attack Wasn&apos;t in Any CVE Database. Your Scanner Missed It.</title><link>https://ottersight.com/blog/2026-04-04-axios-supply-chain-attack/</link><guid isPermaLink="true">https://ottersight.com/blog/2026-04-04-axios-supply-chain-attack/</guid><description>The axios npm supply chain attack hit 100 million weekly downloads and lasted 3 hours. Here&apos;s why traditional vulnerability scanners couldn&apos;t catch it — and what would have.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Claude Code&apos;s Security Review Has a Blind Spot — It Doesn&apos;t Check Your Dependencies</title><link>https://ottersight.com/blog/2026-04-02-claude-code-security-blind-spot/</link><guid isPermaLink="true">https://ottersight.com/blog/2026-04-02-claude-code-security-blind-spot/</guid><description>The leaked Claude Code security prompt reveals a critical gap: dependency vulnerabilities are explicitly excluded. Here&apos;s why that matters and how to fix it.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>We Scanned Ourselves: 86 Vulnerabilities Found (and Fixed) with OtterSight</title><link>https://ottersight.com/blog/2026-04-01-we-scanned-ourselves/</link><guid isPermaLink="true">https://ottersight.com/blog/2026-04-01-we-scanned-ourselves/</guid><description>We used OtterSight&apos;s MCP server to scan our own monorepo. Found 86 vulnerabilities — 5 critical, 1 actively exploited. Fixed all of them. Here&apos;s exactly what happened.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate></item><item><title>What npm audit Actually Misses — And the Three Layers of Dependency Security</title><link>https://ottersight.com/blog/2026-03-29-what-npm-audit-misses/</link><guid isPermaLink="true">https://ottersight.com/blog/2026-03-29-what-npm-audit-misses/</guid><description>npm audit checks one database. Your dependencies face three types of threats. Here&apos;s the full picture and what tools cover each layer.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Your AI Security Audit Has a Blind Spot — It Can&apos;t Check Dependencies</title><link>https://ottersight.com/blog/2026-03-27-ai-security-audit-blind-spot/</link><guid isPermaLink="true">https://ottersight.com/blog/2026-03-27-ai-security-audit-blind-spot/</guid><description>When you ask an AI to audit your code for security issues, it reviews your code patterns. But it has no idea if the 47 packages it installed have known CVEs.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Getting Started with OtterSight CLI — Your First Dependency Scan in 30 Seconds</title><link>https://ottersight.com/blog/2026-03-25-getting-started-cli/</link><guid isPermaLink="true">https://ottersight.com/blog/2026-03-25-getting-started-cli/</guid><description>Install the OtterSight CLI, scan your project for vulnerabilities, and get a security report with SBOM, CVE, EPSS, and KEV data.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate></item><item><title>EUVD Explained — What the EU Vulnerability Database Means for NIS2 Compliance</title><link>https://ottersight.com/blog/2026-03-23-euvd-explained/</link><guid isPermaLink="true">https://ottersight.com/blog/2026-03-23-euvd-explained/</guid><description>A developer&apos;s guide to the EU Vulnerability Database (EUVD): what it is, how it differs from NVD, and why it matters for NIS2 compliance.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Why We Built OtterSight — OSS Dependency Scanning with EU Vulnerability Database</title><link>https://ottersight.com/blog/2026-03-21-why-we-built-ottersight/</link><guid isPermaLink="true">https://ottersight.com/blog/2026-03-21-why-we-built-ottersight/</guid><description>The story behind OtterSight: why we built an open-source SCA scanner that integrates the EU Vulnerability Database (EUVD) for better NIS2 compliance.</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate></item></channel></rss>