<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml">
<url><loc>https://boring.tools/</loc><xhtml:link rel="alternate" hreflang="en" href="https://boring.tools/"/><xhtml:link rel="alternate" hreflang="de" href="https://boring.tools/de/"/><xhtml:link rel="alternate" hreflang="x-default" href="https://boring.tools/"/></url>
<url><loc>https://boring.tools/de/</loc><xhtml:link rel="alternate" hreflang="en" href="https://boring.tools/"/><xhtml:link rel="alternate" hreflang="de" href="https://boring.tools/de/"/><xhtml:link rel="alternate" hreflang="x-default" href="https://boring.tools/"/></url>
<url><loc>https://boring.tools/pricing/</loc><xhtml:link rel="alternate" hreflang="en" href="https://boring.tools/pricing/"/><xhtml:link rel="alternate" hreflang="de" href="https://boring.tools/de/pricing/"/><xhtml:link rel="alternate" hreflang="x-default" href="https://boring.tools/pricing/"/></url>
<url><loc>https://boring.tools/de/pricing/</loc><xhtml:link rel="alternate" hreflang="en" href="https://boring.tools/pricing/"/><xhtml:link rel="alternate" hreflang="de" href="https://boring.tools/de/pricing/"/><xhtml:link rel="alternate" hreflang="x-default" href="https://boring.tools/pricing/"/></url>
<url><loc>https://boring.tools/blog/</loc></url>
<url><loc>https://boring.tools/blog/2026-06-01-eu-cyber-resilience-act-what-it-means-for-your-software/</loc></url>
<url><loc>https://boring.tools/blog/2026-06-09-what-is-an-sbom-and-why-developers-should-care/</loc></url>
<url><loc>https://boring.tools/blog/2026-06-10-miasma-worm-npm-supply-chain/</loc></url>
<url><loc>https://boring.tools/blog/2026-06-10-software-supply-chain-attacks-what-they-are-and-how-to-defend-against-them/</loc></url>
<url><loc>https://boring.tools/blog/2026-06-10-vs-code-extension-update-delay-supply-chain/</loc></url>
<url><loc>https://boring.tools/blog/2026-06-12-owasp-api-security-top-10-2023-what-every-developer-should-know/</loc></url>
<url><loc>https://boring.tools/blog/2026-06-12-owasp-top-10-cicd-security-risks-what-every-pipeline-needs-to-know/</loc></url>
<url><loc>https://boring.tools/blog/2026-07-01-mastra-npm-typosquat-easy-day-js/</loc></url>
<url><loc>https://boring.tools/blog/2026-07-02-polinrider-cross-ecosystem-supply-chain/</loc></url>
<url><loc>https://boring.tools/blog/2026-07-04-github-action-tags-supply-chain/</loc></url>
<url><loc>https://boring.tools/blog/2026-07-08-phantom-squatting-ai-domains/</loc></url>
<url><loc>https://boring.tools/blog/2026-07-10-npm-12-install-scripts-opt-in/</loc></url>
<url><loc>https://boring.tools/blog/2026-07-12-jscrambler-install-time-compromise/</loc></url>
<url><loc>https://boring.tools/blog/2026-07-19-dormant-maintainer-accounts-supply-chain-risk/</loc></url>
<url><loc>https://boring.tools/blog/2026-07-20-vitevenom-import-time-malware/</loc></url>
<url><loc>https://boring.tools/blog/2026-07-25-cra-reporting-deadline-operational-sbom/</loc></url>
<url><loc>https://boring.tools/docs/ai-triage/</loc></url>
<url><loc>https://boring.tools/docs/api/</loc></url>
<url><loc>https://boring.tools/docs/ci/</loc></url>
<url><loc>https://boring.tools/docs/cra-reporting/</loc></url>
<url><loc>https://boring.tools/docs/cve-database/</loc></url>
<url><loc>https://boring.tools/docs/getting-started/</loc></url>
<url><loc>https://boring.tools/docs/organizations/</loc></url>
<url><loc>https://boring.tools/docs/plans-and-billing/</loc></url>
<url><loc>https://boring.tools/docs/projects/</loc></url>
<url><loc>https://boring.tools/docs/sbom/</loc></url>
<url><loc>https://boring.tools/docs/triage/</loc></url>
<url><loc>https://boring.tools/docs/vulnerability-monitoring/</loc></url>
<url><loc>https://boring.tools/legal/imprint/</loc></url>
<url><loc>https://boring.tools/legal/privacy/</loc></url>
<url><loc>https://boring.tools/legal/terms/</loc></url>
</urlset>
