<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>TRUSTIVAN blog</title><description>TRUSTIVAN scans container images for known vulnerabilities and keeps every triage decision, suppression and policy verdict that follows — so a finding has a history, not just a severity.</description><link>https://trustivan.com/</link><item><title>The verdict belongs in the body, not the status code</title><link>https://trustivan.com/blog/the-verdict-belongs-in-the-body/</link><guid isPermaLink="true">https://trustivan.com/blog/the-verdict-belongs-in-the-body/</guid><description>Returning a policy failure as an HTTP error conflates two situations a pipeline must treat differently: the build being wrong, and the tool being unavailable.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Why a finding needs a memory</title><link>https://trustivan.com/blog/why-a-finding-needs-a-memory/</link><guid isPermaLink="true">https://trustivan.com/blog/why-a-finding-needs-a-memory/</guid><description>Every scanner produces a report. Almost none produce a record. That difference is why vulnerability backlogs get ignored, and what TRUSTIVAN is built around.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate></item></channel></rss>