<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Dependably guides</title>
    <link>https://dependably.ca/guides</link>
    <atom:link href="https://dependably.ca/guides/feed.xml" rel="self" type="application/rss+xml" />
    <description>Evergreen how-tos from Dependably on package supply chains, certificates and exposure.</description>
    <language>en</language>
    <item>
      <title>Why a package install returns 403, and what to do</title>
      <link>https://dependably.ca/guides/why-a-package-install-returns-403</link>
      <guid isPermaLink="true">https://dependably.ca/guides/why-a-package-install-returns-403</guid>
      <pubDate>Sat, 05 Sep 2026 12:00:00 GMT</pubDate>
      <description>A 403 from npm, pip or dotnet inside CI usually means a policy said no. How to tell policy from authentication, read the refusal, and fix the right thing.</description>
    </item>
    <item>
      <title>A certificate rotation checklist that reads what was served</title>
      <link>https://dependably.ca/guides/certificate-rotation-checklist</link>
      <guid isPermaLink="true">https://dependably.ca/guides/certificate-rotation-checklist</guid>
      <pubDate>Sat, 05 Sep 2026 12:00:00 GMT</pubDate>
      <description>Renewal jobs fail quietly and rotations install the wrong chain. A short checklist for checking the certificate a server actually serves, from outside.</description>
    </item>
    <item>
      <title>Triage a vulnerability advisory by exposure, not by count</title>
      <link>https://dependably.ca/guides/triage-a-vulnerability-advisory</link>
      <guid isPermaLink="true">https://dependably.ca/guides/triage-a-vulnerability-advisory</guid>
      <pubDate>Sat, 05 Sep 2026 12:00:00 GMT</pubDate>
      <description>When an advisory lands, a scanner lists every occurrence. How to answer which releases ship the package, whether code can reach it, and what to patch first.</description>
    </item>
  </channel>
</rss>
