Anchore
banner
anchore.com
Anchore
@anchore.com
120 followers 1K following 440 posts
Securing and managing the software supply chain. Proud parent of @syftproject.bsky.social and @grypeproject.bsky.social
Posts Media Videos Starter Packs
Pinned
Syft & Grype have hit 40 million downloads!
A massive thank you to the open source community for trusting us to secure their software supply chains.
#OpenSource #SBOM #DevSecOps
https://anchore.com/opensource
The best security teams don't blame; they partner. A themed month won't fix culture.

New blog by @josh.bressers.namehttps://anchore.com/blog/cybersecurity-awareness-month-no-longer-works/
"This is lesson number one when a zero-day disclosure hits: get to the actionable information as fast as possible."

@josh.bressers.name shares Anchore's complete NPM incident response process—from initial ...
https://anchore.com/blog/a-zero-day-incident-response-story-from-the-watchers-on-the-wall/
Scale-out architecture for web-scale environments 📈

Because your containers don't wait for security scans ⏱️

https://anchore.com/platform/secure/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
We don't schedule incident advice for October—so why schedule "awareness"?

@josh.bressers.name on continuous, trust-first security comms.

Post: https://anchore.com/blog/cybersecurity-awareness-month-no-longer-works/
Anchore SBOM Score = CVSS + EPSS + KEV status 📊

Because not all vulnerabilities are created equal ⚠️

https://anchore.com/platform/sbom/

#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Missed the Syft/Grype insights? No worries! Catch the recording of our latest Open Source stream here: #SoftwareSupplyChain
https://www.youtube.com/watch?v=b5MdzKb9Ypc
Live SBOM & Security Fixes: Anchore Devs Improve Syft & Grype (September 18th)
Join our weekly *Open Source Security* live stream! Watch Anchore's Developer Relations and Engineering teams collaborate in real-time on crucial *Software Supply Chain Security* tools. This session focuses on improving *Syft* (for *SBOM* generation) and *Grype* (for *vulnerability scanning*), addressing community-raised issues and pull requests. Every Thursday, "Open Source Gardening" offers a transparent look into maintaining popular *open source security* projects. We'll dive into items marked 'needs discussion' and, time permitting, tackle other interesting contributions. Learn development best practices, understand the challenges of *SBOM* accuracy, and see how *vulnerability scanning* tools evolve. Whether you're a contributor, user, or just curious about *open source security*, tune in to learn and engage with the minds behind Anchore's OSS tools. *Agenda:* - Discuss and resolve issues/PRs tagged 'needs discussion'. - Tackle other high-priority or interesting community contributions for Syft, Grype, and related projects. *Resources & Learn More:* - Learn about SBOMs: [Link to Anchore's SBOM pillar page/guide if available] - Dive into Software Supply Chain Security: [Link to relevant Anchore pillar page/blog if available] - Syft on GitHub: https://github.com/anchore/syft - Grype on GitHub: https://github.com/anchore/grype - Join the Community Discussion: https://anchore.com/discourse - All Anchore Open Source Projects: https://github.com/anchore - Sign-up for the OSS Newsletter: https://get.anchore.com/anchore-community/ #OpenSourceSecurity #SBOM #SoftwareSupplyChainSecurity
www.youtube.com
Our VP of Security @josh.bressers.name on the Sept 8 NPM attack:

"Six hours from compromise to resolution. We used to measure supply chain attacks in weeks."

His behind-the-scenes account of what rapid in...
https://anchore.com/blog/a-zero-day-incident-response-story-from-the-watchers-on-the-wall/
We're LIVE! The Anchore Open Source team is here to chat Syft, Grype, and all things #OpenSource. Jump in and say hi!
https://www.youtube.com/watch?v=b5MdzKb9Ypc
Live in 5 minutes! Join the Anchore Open Source stream NOW for all the Syft & Grype goodness. Your questions, our answers!
https://www.youtube.com/watch?v=b5MdzKb9Ypc
One hour until we go LIVE! Get your questions ready for the Anchore Open Source team – we're talking Syft, Grype & more! #DevTalk
https://www.youtube.com/watch?v=b5MdzKb9Ypc
"Cybersecurity Awareness Month had its moment. It's over."

New from Anchore VP of Security, @Josh Bressers: ditch the calendar ritual/ Instead build trust daily.

Read: https://anchore.com/blog/cybersecurity-awareness-month-no-longer-works/
Psst... tomorrow at 12 PM PT, the Anchore OS crew hits the airwaves! Get your Syft & Grype insights straight from the source. #Grype #Syft
https://www.youtube.com/watch?v=b5MdzKb9Ypc
Oh fixie bikes were always a thing!

Because it's cybersecurity awareness month, Anchore dug through the old NSA security awareness archives and found the best of the best to help raise awareness. These vintage posters from the '50s and '60s serve as a fantastic reminder of manual... www.anchore.com
Got Syft/Grype questions? Our Open Source team is live Thursday at 12 PM PT to tackle bugs, PRs, & future plans. Don't be a stranger! #SBOM
https://www.youtube.com/watch?v=b5MdzKb9Ypc
"You can replace your static contract deliverables with dynamic ones and do review meetings based on Anchore's live data instead of a 2-3 weeks old compliance audit.... https://anchore.com/blog/how-sabel-systems-reduced-vulnerability-review-time-by-75-while-maintaining-zero-critical-vulnerabilities/
"Before Anchore, it would take us 1-2 weeks to go through every vulnerability. Using Anchore has brought that down to 3 days."
—Robert McKay, Sabel Systems

75% fast... https://anchore.com/blog/how-sabel-systems-reduced-vulnerability-review-time-by-75-while-maintaining-zero-critical-vulnerabilities/
Thrilled to share that @anchore's pitch video on software supply chain security has been deemed Awardable by the P1 Solutions Marketplace! Government customers, please check out our 5-minute video solution on https://p1-marketplace.com/.
Don't forget security during the holidays, lock up packages...

Because it's cybersecurity awareness month, Anchore dug through the old NSA security awareness archives and found the best of the best to help raise awareness. These vintage posters from the '50s and '60s serve as a f... www.anchore.com
Your MCP server might be the weakest link—here's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/

#MCP #SoftwareSupplyChain #ContainerSecurity #DevSecOps
Today's software supply chain is more like Einstein's riddle....

Because it's cybersecurity awareness month, we dug through the old NSA security awareness archives and found the best of the best to help raise awareness. These vintage posters from the '50s and '60s serve as a fantastic reminder ....
"With Anchore, we scan for vulns directly in our k8s cluster. No SSHing into prod pods. We get a zero-trust posture and a secure software supply chain."
—Robert McKa... https://anchore.com/blog/how-sabel-systems-reduced-vulnerability-review-time-by-75-while-maintaining-zero-critical-vulnerabilities/
@josh.bressers.name scanned 161 MCP containers. Found 9k vulnerabilities. 263 were critical.
"Software ages like milk, not wine." His analysis breaks down what's actually being deployed in the MCP ecosystem and what to do about it. https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
Somebody needs to petition for those canaries....

Because it's cybersecurity awareness month, we dug through the old NSA security awareness archives and found the best of the best to help raise awareness. These vintage posters from the '50s and '60s serve as a fantastic reminder of manual secur....
🚀 New hardened container companies are launching constantly.

The reason isn't compliance mandates—it's practical necessity.

When scanners got accurate, the vulnerability problem became impossible to ignore. Hardened images are the effi...
https://anchore.com/blog/hardened-images-are-here-to-stay/