<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>漏洞管理 on 黄文卓 | DevOps Engineer</title><link>https://socake.github.io/tags/%E6%BC%8F%E6%B4%9E%E7%AE%A1%E7%90%86/</link><description>Recent content in 漏洞管理 on 黄文卓 | DevOps Engineer</description><generator>Hugo -- gohugo.io</generator><language>zh-CN</language><managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor><webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster><copyright>© 2026 Wenzhuo Huang</copyright><lastBuildDate>Fri, 24 Oct 2025 10:00:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/tags/%E6%BC%8F%E6%B4%9E%E7%AE%A1%E7%90%86/index.xml" rel="self" type="application/rss+xml"/><item><title>SBOM 生成与 Dependency-Track 漏洞管理实战</title><link>https://socake.github.io/posts/sbom-dependency-track/</link><pubDate>Fri, 24 Oct 2025 10:00:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/posts/sbom-dependency-track/</guid><description>一份基于生产环境的 SBOM 实战指南：讲清楚 CycloneDX 与 SPDX 的格式差异、Syft/cdxgen/Trivy 三款主流生成器的对比，部署 Dependency-Track 4.12 做持续漏洞监测，通过策略违规自动化处置 CVE，并分享 SBOM 消费链路上的真实踩坑。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/sbom-dependency-track/featured.jpg"/></item></channel></rss>