We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- Anchore Enterprise is now SPDX 3 Ready (today)
- NPM Supply Chain Breach Response for Anchore Enterprise and Grype Users (4 days ago)
- DevOpsDays Washington, DC (5 days ago)
- Navigating the New Compliance Frontier (6 days ago)
- Sabel Systems Leverages Anchore SBOM and SECURE to Scale Compliance While Reducing Vulnerability Review Time by 75% (1 week ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- September 18th | Open Source Gardening | Live Stream (today)
- Anchore Open Source Weekly Report, Week 37, 2025 (today)
- Why SBOM contains configuration files? (today)
- Should I create a template, or just post-process to get an SPDX SBOM containing PURLs only? (4 days ago)
- Update: Raise in false positives due to missing NVD overrides (4 days ago)