We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- Supply Chain Security made the OWASP Top Ten, this changes nothing (today)
- Anchore Welcomes SBOM Pioneer Dr. Allan Friedman as Board Advisor (2 days ago)
- Anchore Enterprise 5.23: CycloneDX VEX and VDR Support (6 days ago)
- The EU CRA “Compliance Cascade”: Why Your Customers (and Acquirers) Now Demand a Verifiable DevSecOps Pipeline (1 week ago)
- Security Without Friction: How RepoFlow Created a DevSecOps Package Manager with Grype (2 weeks ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- November 6 | Open Source Gardening | Live Stream (1 week ago)
- Does grype fully handle the Trivy based SBOM vulnerability analysis? (1 week ago)
- Does grype covers urls instead of version in npm? (1 week ago)
- October 23rd 2025 | Open Source Gardening | Live Stream (1 week ago)
- October 16th 2025 | Open Source Gardening | Live Stream (2 weeks ago)
