We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- Time to Take Another Look at Grype: A Year of Major Improvements (2 days ago)
- How to Use Anchore & DefectDojo to Stand Up Your DevSecOps Function (3 days ago)
- SPDX 3.0: From Software Inventory to System Risk Orchestration (4 days ago)
- How to Respond When Your Customers Require an SBOM (and Even Write It Into the Contract!) (1 week ago)
- The SBOM Paradox: Why ‘Useless’ Today Means Essential Tomorrow (2 weeks ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- Errors when using the syft image in a Cloud pipeline (1 day ago)
- Another look at Grype - New Features (2 days ago)
- Database cleanup (4 days ago)
- June 26th | Open Source Gardening | Live Stream (5 days ago)
- Anchore Open Source Weekly Report, Week 25, 2025 (5 days ago)