We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- The DoD SWFT Initiative and the Promise of cATO Fulfilled (1 week ago)
- Beyond the Bottleneck: How RAISE 2.0 is Transforming Navy DevSecOps (2 weeks ago)
- Under the Hood: How Anchore’s Enterprise Vulnerability Feeds Keep You Secure (3 weeks ago)
- STIG in Action: 4 Lessons on Automating Compliance with MITRE SAF (4 weeks ago)
- The Top Ten List: The 2025 Anchore Blog (1 month ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- Missing package identification from .zap packaging (1 day ago)
- Evaluating Anchore Score Alignment with ISO/SAE 21434 and Automotive Functional Safety Risk (4 days ago)
- CVE fallback for other ecosystems (6 days ago)
- Help with new provider (1 week ago)
- Grype is reporting a high number of vulnerabilities in one instance, while the other scan returns zero findings. (2 weeks ago)
