We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- Meeting 2025’s SBOM Compliance Deadlines: A Practical Implementation Guide (3 days ago)
- Accelerate & Secure: Optimizing Your Software Supply Chain with DevSecOps (1 week ago)
- Anchore is Excited to Announce it’s Inclusion in the IBM PDE Factory: An Open Source-Powered Secure Software Development Platform (1 week ago)
- Container Drift, Base Images, & CMMC: Solving Public Sector Security Challenges (2 weeks ago)
- From Cost Center to Revenue Driver: How Compliance Became Security’s Best Friend (2 weeks ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- Grype - v0.97.2 released (1 day ago)
- Syft - v1.30.0 released (1 day ago)
- Indirect matches (vulnerabilities affecting the upstream packages) are sometimes too broad (5 days ago)
- Grype on-screen vulnerability count differs from the text file output count (6 days ago)
- Anchore Open Source Weekly Report - Week 31, 2025 (6 days ago)