We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- Security Without Friction: How RepoFlow Created a DevSecOps Package Manager with Grype (2 days ago)
- Beyond The CVE: Deep Container Analysis with Anchore (4 days ago)
- Breaking the Vulnerability Management Cycle with Anchore and Echo (5 days ago)
- Anchore Enterprise 5.22: OpenVEX, PURLs, and RHEL EUS Support (1 week ago)
- Compliance Isn’t an Annual Ritual Anymore (1 week ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- October 23rd 2025 | Open Source Gardening | Live Stream (1 day ago)
- October 16th 2025 | Open Source Gardening | Live Stream (2 days ago)
- October 9th 2025 | Open Source Gardening | Live Stream (2 days ago)
- October 30 | Open Source Gardening | Live Stream (4 days ago)
- Syft is not scanning jar files which are integrated to docker image (1 week ago)
