We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- How to Respond When Your Customers Require an SBOM (and Even Write It Into the Contract!) (3 days ago)
- The SBOM Paradox: Why ‘Useless’ Today Means Essential Tomorrow (1 week ago)
- SCA vs. SBOM: How They Differ & Why They Work Best as a Team (2 weeks ago)
- False Positives and False Negatives in Vulnerability Scanning: Lessons from the Trenches (3 weeks ago)
- NIS2 Compliance with SBOMs: a Scalable, Secure Supply Chain Solution (3 weeks ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- Support SBOM addition and subtraction (today)
- How to tell where vulnerability is in large repo? (1 day ago)
- How to scan 2 directories at one time (3 days ago)
- June 19th | Open Source Gardening | Live Stream (4 days ago)
- Anchore Open Source Weekly Report - Week 24, 2025 (4 days ago)