We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- The Evolution of SBOMs in the DevSecOps Lifecycle: From Planning to Production (6 days ago)
- Choosing the Right SBOM Generator: A Framework for Success (1 week ago)
- 2024 Software Supply Chain Security Report (2 weeks ago)
- Anchore on AWS Marketplace and joins ISV Accelerate (2 weeks ago)
- Anchore Survey 2024: Only 1 in 5 organizations have full visibility of open source (3 weeks ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- False positive on a custom image with custom python package (3 days ago)
- Matching vulnerabilities using upstream without versions (4 days ago)
- Removing epoch in rpm version (4 days ago)
- Version is parsed from Jar file name instead of Manifest file (5 days ago)
- Kernel headers ignore (6 days ago)