We've launched a dedicated docs site to capture the things that don't fit neatly into a README.
Read the launch post by @alexgoodman87: https://anchore.com/blog/anchore-oss-docs-have-a-new-home/
We've launched a dedicated docs site to capture the things that don't fit neatly into a README.
Read the launch post by @alexgoodman87: https://anchore.com/blog/anchore-oss-docs-have-a-new-home/
"Anchore scans SBOMs built whenever: five months from now, six months ago, 30 years in the future."
When the next zero-day hits, will you spend months... https://anchore.com/blog/the-death-of-manual-sbom-management-and-an-automated-future/
"Anchore scans SBOMs built whenever: five months from now, six months ago, 30 years in the future."
When the next zero-day hits, will you spend months... https://anchore.com/blog/the-death-of-manual-sbom-management-and-an-automated-future/
On @techstronggroup.bsky.social, our VP Security Josh Bressers warns of "Hidden Dependencies": AI copies vulnerable logic but skips the package manifest your scann... https://techstrong.ai/contributed-content/the-curious-case-of-ai-dependencies/
On @techstronggroup.bsky.social, our VP Security Josh Bressers warns of "Hidden Dependencies": AI copies vulnerable logic but skips the package manifest your scann... https://techstrong.ai/contributed-content/the-curious-case-of-ai-dependencies/
We've added new DISA STIG profiles for Tomcat and NGINX. Automate validation for your web servers and speed up your authorization process.
https://anchore.com/blog/anchore-enterprise-5-24/
We've added new DISA STIG profiles for Tomcat and NGINX. Automate validation for your web servers and speed up your authorization process.
https://anchore.com/blog/anchore-enterprise-5-24/
9,000 vulns
263 critical findings
36K+ NPM packages
Outdated base images
Not fear-mongering—just data-driven real... https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
#MCP #ContainerSecurity
9,000 vulns
263 critical findings
36K+ NPM packages
Outdated base images
Not fear-mongering—just data-driven real... https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
#MCP #ContainerSecurity
Until you try to manage thousands of them 📊
Scale is everything 📈
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Until you try to manage thousands of them 📊
Scale is everything 📈
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Catch violations before deployment, not during audits 🛡️
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
Catch violations before deployment, not during audits 🛡️
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
"Software ages like milk, not wine." His analysis breaks down what's actually being deployed in the MCP ecosystem and what to do about it. https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
"Software ages like milk, not wine." His analysis breaks down what's actually being deployed in the MCP ecosystem and what to do about it. https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
It's a contributor time-shortage problem. Our Dir of DevRel @popey.me wondered if an AI could help. So ... https://anchore.com/blog/can-an-llm-really-fix-a-bug-a-start-to-finish-case-study/
It's a contributor time-shortage problem. Our Dir of DevRel @popey.me wondered if an AI could help. So ... https://anchore.com/blog/can-an-llm-really-fix-a-bug-a-start-to-finish-case-study/
👉 https://anchore.com/blog/grants-release-0-3-0-smarter-policies-faster-scans-and-simpler-compliance/
#OpenSource #SupplyChainSecurity #Compliance #DevSecOps
👉 https://anchore.com/blog/grants-release-0-3-0-smarter-policies-faster-scans-and-simpler-compliance/
#OpenSource #SupplyChainSecurity #Compliance #DevSecOps
Don't let your container images become a blind spot. @tyranhenry breaks down the best practices for securing Rust crates in our latest blog.
https://anchore.com/blog/beyond-cargo-audit-securing-your-rust-crates-in-container-images/
Don't let your container images become a blind spot. @tyranhenry breaks down the best practices for securing Rust crates in our latest blog.
https://anchore.com/blog/beyond-cargo-audit-securing-your-rust-crates-in-container-images/
Syft, Grype, and Grant have grown way beyond a single GitHub page. We finally built a space that matches the maturity of our tools. @alexgoodman87, introduces oss.anchore.com—the new home for Anch... https://anchore.com/blog/anchore-oss-docs-have-a-new-home/
Syft, Grype, and Grant have grown way beyond a single GitHub page. We finally built a space that matches the maturity of our tools. @alexgoodman87, introduces oss.anchore.com—the new home for Anch... https://anchore.com/blog/anchore-oss-docs-have-a-new-home/
👉 https://go.anchore.com/anchore-enterprise-Q4-release.html
👉 https://go.anchore.com/anchore-enterprise-Q4-release.html
"Establishing trust starts with verifying the provenance of OSS code and validating supplier SBOMs."
At enterprise scale, you can't trust what you can't verify. https://anchore.com/blog/the-death-of-manual-sbom-management-and-an-automated-future/
"Establishing trust starts with verifying the provenance of OSS code and validating supplier SBOMs."
At enterprise scale, you can't trust what you can't verify. https://anchore.com/blog/the-death-of-manual-sbom-management-and-an-automated-future/
#DevSecOps #Cybersecurity #SupplyChainSecurity
#DevSecOps #Cybersecurity #SupplyChainSecurity
Josh Bressers (Anchore) joined the Pauls Security Weekly show to explain why the panic over the React vuln was misplaced, and why Next.js defaults are the real danger zone (34:20).
He also dives int...
https://youtu.be/e6yvNJnGRM8?si=X6UJ21-xAfLZTN6P&t=2062
Josh Bressers (Anchore) joined the Pauls Security Weekly show to explain why the panic over the React vuln was misplaced, and why Next.js defaults are the real danger zone (34:20).
He also dives int...
https://youtu.be/e6yvNJnGRM8?si=X6UJ21-xAfLZTN6P&t=2062
👉 https://go.anchore.com/anchore-enterprise-Q4-release.html
👉 https://go.anchore.com/anchore-enterprise-Q4-release.html
New in Anchore Enterprise 5.24: Paste a CVE or Advisory ID into a single search field to instantly see your total exposure across all SBOMs and images. Rapid response just got faster.
https://anchore.com/blog/anchore-enterprise-5-24/
New in Anchore Enterprise 5.24: Paste a CVE or Advisory ID into a single search field to instantly see your total exposure across all SBOMs and images. Rapid response just got faster.
https://anchore.com/blog/anchore-enterprise-5-24/
On the @techstronggroup.bsky.social AI blog, he explains how AI hallucinations allow attackers to hijack your builds. AI doe...
https://techstrong.ai/contributed-content/the-curious-case-of-ai-dependencies/
On the @techstronggroup.bsky.social AI blog, he explains how AI hallucinations allow attackers to hijack your builds. AI doe...
https://techstrong.ai/contributed-content/the-curious-case-of-ai-dependencies/
Check out @tyranhenry's guide on using cargo-auditable to make your containers fully transparent to...
https://anchore.com/blog/beyond-cargo-audit-securing-your-rust-crates-in-container-images/
Check out @tyranhenry's guide on using cargo-auditable to make your containers fully transparent to...
https://anchore.com/blog/beyond-cargo-audit-securing-your-rust-crates-in-container-images/
You need a strategy that covers you when things go off-script.
See how Anchore x @chainguard.dev keeps you ... https://anchore.com/blog/start-safe-stay-secure-anchore-and-chainguard-libraries/
You need a strategy that covers you when things go off-script.
See how Anchore x @chainguard.dev keeps you ... https://anchore.com/blog/start-safe-stay-secure-anchore-and-chainguard-libraries/
On Paul's Security Weekly, Josh Bressers discusses why surface-level SBOMs fail. If you aren't unzipping the "jars within jars," you are missing y...
https://youtu.be/e6yvNJnGRM8?si=U33AHltjh3FbnoY9&t=2816
On Paul's Security Weekly, Josh Bressers discusses why surface-level SBOMs fail. If you aren't unzipping the "jars within jars," you are missing y...
https://youtu.be/e6yvNJnGRM8?si=U33AHltjh3FbnoY9&t=2816
Anchore Enterprise 5.24 lets you apply policy gates to imported SBOMs. Automatically block builds if a third-party SBOM violates your security standards. Turn visibility into enforcement.
https://anchore.com/blog/anchore-enterprise-5-24/
Anchore Enterprise 5.24 lets you apply policy gates to imported SBOMs. Automatically block builds if a third-party SBOM violates your security standards. Turn visibility into enforcement.
https://anchore.com/blog/anchore-enterprise-5-24/