<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Jorg Sowa</title><description>Writing about open source, PHP internals, static analysis, and software security.</description><link>https://jorgsowa.me/</link><item><title>Harden Your Session Cookie Configuration in PHP, PHP 8.6 RFC</title><link>https://jorgsowa.me/posts/2026-06-16-securing-php-session-defaults/</link><guid isPermaLink="true">https://jorgsowa.me/posts/2026-06-16-securing-php-session-defaults/</guid><description>How I got an RFC merged into php-src that tightens session cookie defaults (use_strict_mode, httponly, and SameSite) after years of them lagging behind security recommendations.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Hello World</title><link>https://jorgsowa.me/posts/2026-03-25-hello-world/</link><guid isPermaLink="true">https://jorgsowa.me/posts/2026-03-25-hello-world/</guid><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate></item></channel></rss>