We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- We have no crystal ball but we do have some directions for 2026 (1 week ago)
- The EOL Trap: Why Supply Chain Risk is Often Born of Neglect, Not Malice (1 week ago)
- The “S” in SBOM is for system (2 weeks ago)
- Assemble (2 weeks ago)
- Threat Intelligence and Hunting Summit (2 weeks ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- Recommended Workflow for Large-Scale Recurring SBOM Scans with Syft and Grype (1 day ago)
- Missing package identification from .zap packaging (3 weeks ago)
- Evaluating Anchore Score Alignment with ISO/SAE 21434 and Automotive Functional Safety Risk (3 weeks ago)
- CVE fallback for other ecosystems (3 weeks ago)
- Help with new provider (1 month ago)
