@anchorei
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Securing and managing the software supply chain. Proud parent of @SyftProject and @GrypeProject.
Santa Barbara, CA
Joined June 2009
- Tweets5K
- Following1.3K
- Followers2.8K
- Likes1.6K
Soften the image to pass the scan, or run two STIG workflows. That's the current choice for shell-less container images. Anchore Enterprise runs STIG checks on @chainguard_dev images either way, no shell required. Join our live demo Sept 24 go.anchore.com/running-STIG-…
DevSecOps Update 🔥 Learn how the US Navy achieved ATO in 3-5 days, reduced time spent on #compliance reporting, and reduced #vulnerability overload with Anchore and Sigma Defense. More here 👉 anchore.com/wp-content/uploa…
Kubernetes environments change constantly. Your compliance checks cannot happen just once a year. Compliance Operations builds audit readiness directly into your system lifecycle. See how: anchore.com/blog/compliance-…
CMMC Phase 2 is paused. Phase 1 self-assessment and DFARS 252.204-7012 are not.
Our latest blog covers why continuous evidence beats waiting to see what CMMC becomes.
anchore.com/blog/fedramp-cmm…
Live in an hour: STIG checks on shell-less @chainguard_dev images, demoed live.
Final call to sign up: go.anchore.com/running-STIG-…
Zero-day incidents like Log4Shell highlight the need for a better way to respond. This on-demand webinar explains how an SBOM-powered approach gives the visibility to go from discovering a new vulnerability to creating a remediation list in minutes. go.anchore.com/rapid-inciden… #SBOM
Enter a CVE ID or package name, and instantly get every affected image across your fleet. No new scan, just a simple query. We wrote a deeper walkthrough on scripting the full blast-radius calculation using the Anchore Enterprise API. anchore.com/blog/what-your-v…
Tomorrow: live STIG checks on shell-less @chainguard_dev images, with Anchore + Chainguard.
Last chance to sign up: go.anchore.com/running-STIG-…
FedRAMP renamed itself (Authorization → Certification, Classes A-D).
CMMC Phase 2 got paused. Both within 2 weeks of each other.
On our blog: what actually changed, and what didn't, for your ATO. anchore.com/blog/fedramp-cmm…
New in Anchore Enterprise v6.2: an MCP Server for AI agents.
Direct access to SBOMs, vuln data, and policy results, no brittle API scripts. anchore.com/blog/extending-s…
We're pulling a shell-less @chainguard_dev image live and running it through Anchore's policy engine, straight through to the STIG audit trail your ATO reviewer will ask for.
Sept 24, 10am PT.
go.anchore.com/running-STIG-…
🎯 Serving the defense industrial base? @dfsoftwareinc meets #DoD requirements with air-gapped vulnerability scans. Read their success story with @anchore. 🔗 anchore.com/wp-content/uploa… #DIB
While everyone's debating SBOM formats, the real revolution is happening:
❌ Software inventory
✅ System risk orchestrator
Legacuy SBOMs weren't built for distributed architectures where risk flows through connections, not just components.
🔗 anchore.com/blog/spdx-3-0-fr…
#SBOM
No CVE yet, just a known-bad package? Our blog walks through the use of Anchore Enterprise's API to query by package version instead of waiting for an ID to exist. anchore.com/blog/what-your-v…
New in Anchore Enterprise v6.2: native AI model detection.
GGUF files and Docker Models now get indexed as packages in your SBOM catalog, just like your open source deps. anchore.com/blog/extending-s…
Automate #FedRAMP scanning in CI/CD with Anchore Enterprise. Secure your containers within the 30-day window. Details: anchore.com/fedramp/ #ContainerSecurity #DevSecOps
For security engineering leaders: A detailed guide to the FedRAMP authorization process. Learn about the framework, roles, & a structured approach to achieving compliance. Essential for SaaS/PaaS/IaaS providers targeting the public sector. get.anchore.com/unlocking-th…
Supply chain attacks ↗️ 742% in 2023
Your traditional security stack wasn't built for this fight.
SBOM-first architecture changes everything ⚡
anchore.com/platform/
#SoftwareSupplyChain #SBOM #CyberSecurity
Anchore Enterprise v6.2 is out.
New: native AI model detection in your SBOM, an MCP Server for AI agents, VEX-aware policy, and severity filtering.
anchore.com/blog/extending-s…
#SBOM
BOD 26-04 dropped CVSS-only prioritization: worst case, a 3-day remediation clock. FedRAMP moved its deadline up to Dec 7, 2026. anchore.com/blog/silence-is-…