@anchore

Securing and managing the software supply chain. Proud parent of @SyftProject and @GrypeProject.

Santa Barbara, CA
Joined June 2009
Soften the image to pass the scan, or run two STIG workflows. That's the current choice for shell-less container images. Anchore Enterprise runs STIG checks on @chainguard_dev images either way, no shell required. Join our live demo Sept 24 go.anchore.com/running-STIG-…
68
DevSecOps Update 🔥 Learn how the US Navy achieved ATO in 3-5 days, reduced time spent on #compliance reporting, and reduced #vulnerability overload with Anchore and Sigma Defense. More here 👉 anchore.com/wp-content/uploa…
1
106
Kubernetes environments change constantly. Your compliance checks cannot happen just once a year. Compliance Operations builds audit readiness directly into your system lifecycle. See how: anchore.com/blog/compliance-…
1
73
CMMC Phase 2 is paused. Phase 1 self-assessment and DFARS 252.204-7012 are not. Our latest blog covers why continuous evidence beats waiting to see what CMMC becomes. anchore.com/blog/fedramp-cmm…
69
Live in an hour: STIG checks on shell-less @chainguard_dev images, demoed live. Final call to sign up: go.anchore.com/running-STIG-…
53
Zero-day incidents like Log4Shell highlight the need for a better way to respond. This on-demand webinar explains how an SBOM-powered approach gives the visibility to go from discovering a new vulnerability to creating a remediation list in minutes. go.anchore.com/rapid-inciden… #SBOM
1
1
66
Enter a CVE ID or package name, and instantly get every affected image across your fleet. No new scan, just a simple query. We wrote a deeper walkthrough on scripting the full blast-radius calculation using the Anchore Enterprise API. anchore.com/blog/what-your-v…
1
120
Tomorrow: live STIG checks on shell-less @chainguard_dev images, with Anchore + Chainguard. Last chance to sign up: go.anchore.com/running-STIG-…
54
FedRAMP renamed itself (Authorization → Certification, Classes A-D). CMMC Phase 2 got paused. Both within 2 weeks of each other. On our blog: what actually changed, and what didn't, for your ATO. anchore.com/blog/fedramp-cmm…
65
New in Anchore Enterprise v6.2: an MCP Server for AI agents. Direct access to SBOMs, vuln data, and policy results, no brittle API scripts. anchore.com/blog/extending-s…
5
3
124
We're pulling a shell-less @chainguard_dev image live and running it through Anchore's policy engine, straight through to the STIG audit trail your ATO reviewer will ask for. Sept 24, 10am PT. go.anchore.com/running-STIG-…
70
🎯 Serving the defense industrial base? @dfsoftwareinc meets #DoD requirements with air-gapped vulnerability scans. Read their success story with @anchore. 🔗 anchore.com/wp-content/uploa… #DIB
78
While everyone's debating SBOM formats, the real revolution is happening: ❌ Software inventory ✅ System risk orchestrator Legacuy SBOMs weren't built for distributed architectures where risk flows through connections, not just components. 🔗 anchore.com/blog/spdx-3-0-fr… #SBOM
1
69
No CVE yet, just a known-bad package? Our blog walks through the use of Anchore Enterprise's API to query by package version instead of waiting for an ID to exist. anchore.com/blog/what-your-v…
128
New in Anchore Enterprise v6.2: native AI model detection. GGUF files and Docker Models now get indexed as packages in your SBOM catalog, just like your open source deps. anchore.com/blog/extending-s…
93
Automate #FedRAMP scanning in CI/CD with Anchore Enterprise. Secure your containers within the 30-day window. Details: anchore.com/fedramp/ #ContainerSecurity #DevSecOps
1
40
For security engineering leaders: A detailed guide to the FedRAMP authorization process. Learn about the framework, roles, & a structured approach to achieving compliance. Essential for SaaS/PaaS/IaaS providers targeting the public sector. get.anchore.com/unlocking-th…
65
Supply chain attacks ↗️ 742% in 2023 Your traditional security stack wasn't built for this fight. SBOM-first architecture changes everything ⚡ anchore.com/platform/ #SoftwareSupplyChain #SBOM #CyberSecurity
54
Anchore Enterprise v6.2 is out. New: native AI model detection in your SBOM, an MCP Server for AI agents, VEX-aware policy, and severity filtering. anchore.com/blog/extending-s… #SBOM
1
68
BOD 26-04 dropped CVSS-only prioritization: worst case, a 3-day remediation clock. FedRAMP moved its deadline up to Dec 7, 2026. anchore.com/blog/silence-is-…
1
100