Anchore
banner
anchore.com
Anchore
@anchore.com
120 followers 1K following 460 posts
Securing and managing the software supply chain. Proud parent of @syftproject.bsky.social and @grypeproject.bsky.social
Posts Media Videos Starter Packs
Pinned
Syft & Grype have hit 40 million downloads!
A massive thank you to the open source community for trusting us to secure their software supply chains.
#OpenSource #SBOM #DevSecOps
https://anchore.com/opensource
"The feature that unlocks adoption often isn't the one you set out to build."

For @RepoFlow_io, that feature was security.

With Anchore's @GrypeProject + @SyftProject, they built scan...
https://anchore.com/blog/security-without-friction-how-repoflow-created-a-devsecops-package-manager-with-grype/
Policy failure—not zero-days—is the real weak link.

Anchore enforces what "secure" means before bad configs & secrets ever ship.

Read @JoshSopuru's Beyond t... https://anchore.com/blog/beyond-the-cve-deep-container-analysis-with-anchore/

#SBOM #ContainerSecurity #PolicyAsCode #SoftwareSupplyChain
How to add vulnerability scanning to developer tools?

@RepoFlow's pattern:

1. Generate SBOMs with Syft
2. Scan SBOMs with Grype
3. Parse JSON, deduplicate CVEs
4. Display in existing ... https://anchore.com/blog/security-without-friction-how-repoflow-created-a-devsecops-package-manager-with-grype/
"It's starting to feel like 2025 is going to be the year of IT compliance"

@josh.bressers.name on why CRA, PLD, DORA, and SSDF updates mean we need CompOps—treating compliance like a DevOps problem, not a security victory lap:

https://anchore.com/blog/compliance-isnt-an-annual-ritual-anymore/
Cloud Native Now 2025 is TODAY! Join us & learn how to master cloud native securely across all your infra. Don't miss our session: How to Generate an SBOM wi... https://www.techstrongevents.com/cloud-native-now-2025/home?ref=sponsor-invites&utm_source=hs&utm_medium=email&utm_campaign=sponsor-invites
Research shows 97% of component vulnerabilities aren't exploitable in final products.

Your customers don't know this. They just see the scanner results.

Anchore 5.22 adds OpenVEX support. Stop explaining. Start exporting.

https://anchore.com/blog/anchore-enterprise-5-22/
Syft & Grype have hit 40 million downloads!
A massive thank you to the open source community for trusting us to secure their software supply chains.
#OpenSource #SBOM #DevSecOps
https://anchore.com/opensource
Relying on CVE scans alone is like putting a padlock on a vault with the back door open.

Anchore goes beyond the CVE to secure configs, secrets &... @JoshSopuru https://anchore.com/blog/beyond-the-cve-deep-container-analysis-with-anchore/

#SBOM #ContainerSecurity #PolicyAsCode #SoftwareSupplyChain
95% of companies see limited ROI from GenAI. Why? It's a risk problem. ⚠️
Join us Nov 12, 2025, for the live unveiling of the Generative AI in Risk... https://executiveitforums.org/11011-cpe-generative-ai-in-risk-and-compliance-insights-from-the-2025-industry-report
#GenAI #Risk #Compliance #Webinar
"When security teams do their jobs, the result is nothing. 'Nothing' can't be measured."

But compliance requirements? Those ARE measurable.

@josh.bressers.name breaks down why CompOps is the future and how to make continuous com...
https://anchore.com/blog/compliance-isnt-an-annual-ritual-anymore/
False positives from RHEL EUS? Not anymore.

Anchore 5.22 detects EUS content automatically for accurate vulnerability reports.

Learn what's new → https://anchore.com/blog/anchore-enterprise-5-22/

#OpenVex #PURL #SoftwareSupplyChain #VulnerabilityManagement
[email protected] has a warning for security teams:

"Security teams love to play the hero…if you do this when building out a compliance program, you've lost before you started."

His take on CompOps and why DevOps holds the an...
https://anchore.com/blog/compliance-isnt-an-annual-ritual-anymore/
You can't patch every CVE—but you can explain every one.

Anchore 5.22 brings VEX annotations + OpenVEX export to make vulnerability data contextual and credible.

https://anchore.com/blog/anchore-enterprise-5-22/

#OpenVex #PURL #SoftwareSupplyChain #VulnerabilityManagement
@josh.bressers.name: "If you can't search your past builds, you can't bound your blast radius. SBOMs turn a frantic morning into a simple query."

https://anchore.com/blog/a-zero-day-incident-response-story-from-the-watchers-on-the-wall/
CRA demands SBOMs stored for 10 years. PCI-DSS 4 requires scans every 3 months minimum.

Compliance isn't annual anymore—it's continuous.

@josh.bressers.name explains why your DevOps team already knows how to solve this problem:

https://anchore.com/blog/compliance-isnt-an-annual-ritual-anymore/
The best security teams don't blame; they partner. A themed month won't fix culture.

New blog by @josh.bressers.namehttps://anchore.com/blog/cybersecurity-awareness-month-no-longer-works/
"This is lesson number one when a zero-day disclosure hits: get to the actionable information as fast as possible."

@josh.bressers.name shares Anchore's complete NPM incident response process—from initial ...
https://anchore.com/blog/a-zero-day-incident-response-story-from-the-watchers-on-the-wall/
Scale-out architecture for web-scale environments 📈

Because your containers don't wait for security scans ⏱️

https://anchore.com/platform/secure/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
We don't schedule incident advice for October—so why schedule "awareness"?

@josh.bressers.name on continuous, trust-first security comms.

Post: https://anchore.com/blog/cybersecurity-awareness-month-no-longer-works/
Anchore SBOM Score = CVSS + EPSS + KEV status 📊

Because not all vulnerabilities are created equal ⚠️

https://anchore.com/platform/sbom/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps