We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- The “S” in SBOM is for system (6 days ago)
- Assemble (6 days ago)
- Threat Intelligence and Hunting Summit (6 days ago)
- Beyond the SBOM: Defending the Software Supply Chain Against Modern Attacks (6 days ago)
- Risk in Real Time: Continuous Monitoring & Cyber Resilience (6 days ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- Missing package identification from .zap packaging (1 week ago)
- Evaluating Anchore Score Alignment with ISO/SAE 21434 and Automotive Functional Safety Risk (2 weeks ago)
- CVE fallback for other ecosystems (2 weeks ago)
- Help with new provider (3 weeks ago)
- Grype is reporting a high number of vulnerabilities in one instance, while the other scan returns zero findings. (3 weeks ago)