<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Provally Blog</title><description>Research, engineering notes, and product updates from Provally.</description><link>https://provally.io/</link><language>en-us</language><item><title>Better CVE-Based SAST Rules Start with the Right Patch</title><link>https://provally.io/blog/better-cve-based-sast-rules-start-with-the-right-patch/</link><guid isPermaLink="true">https://provally.io/blog/better-cve-based-sast-rules-start-with-the-right-patch/</guid><description>How we rebuilt CVE Tracer’s Patch Finding Agent for GrepRules and improved correct patch attribution from 21% to 77%.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate><category>SAST</category><category>Engineering</category><category>Vulnerability Research</category><author>Provally</author></item><item><title>Launching greprules.io and greprules Plugin: Free SAST Rules for the AI Coding Era</title><link>https://provally.io/blog/greprules-free-sast-rule-hub/</link><guid isPermaLink="true">https://provally.io/blog/greprules-free-sast-rule-hub/</guid><description>Meet greprules.io and the greprules Plugin: a free way to discover and use OpenGrep/Semgrep-compatible SAST rules in developer and AI coding workflows.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><category>Product</category><category>SAST</category><category>Open Source</category><author>Provally</author></item><item><title>CVE to SAST Rule Generation: How We Build OpenGrep Rules from Real Patches</title><link>https://provally.io/blog/cve-to-sast/</link><guid isPermaLink="true">https://provally.io/blog/cve-to-sast/</guid><description>How Provally turns public CVEs into OpenGrep-compatible SAST rules using patch attribution, root-cause analysis, and validation against real commits.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>SAST</category><category>Engineering</category><category>Vulnerability Research</category><author>Provally</author></item><item><title>RSAC 2026 Application Security: What AI Changed Isn’t Detection — It’s the Way We Prove</title><link>https://provally.io/blog/rsac-2026-appsec-en/</link><guid isPermaLink="true">https://provally.io/blog/rsac-2026-appsec-en/</guid><description>Why SAST noise persists, how PoC-based verification proves real exploitability, and where AI-assisted AppSec workflows deliver value.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate><category>AppSec</category><category>AI Security</category><category>Industry</category><author>Provally</author></item></channel></rss>