We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- Generating SBOMs for JavaScript Projects: A Developer’s Guide (today)
- Truth in IT: Keeping Your Code Shipshape with SBOMs! (2 days ago)
- The Developer’s Guide to SBOMs & Policy-as-Code (3 days ago)
- Contributing to Vulnerability Data: Making Security Better for Everyone (1 week ago)
- Software Supply Chain Transparency: Why SBOMs Are the Missing Piece in Your ConMon Strategy (1 week ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- Add OS related information on language based packages (3 days ago)
- Understanding Syft's Software Detection Mechanism and Architecture (3 days ago)
- Anchore Open Source Weekly Report - Week 12, 2025 (4 days ago)
- Does Syft automaticaly detects existing SBOM files? (1 week ago)
- March 20th | Open Source Gardening | Live Stream (1 week ago)