We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- The Critical Role of SBOMs in PCI DSS 4.0 Compliance (1 day ago)
- Generating SBOMs for JavaScript Projects: A Developer’s Guide (5 days ago)
- Truth in IT: Keeping Your Code Shipshape with SBOMs! (1 week ago)
- The Developer’s Guide to SBOMs & Policy-as-Code (1 week ago)
- Contributing to Vulnerability Data: Making Security Better for Everyone (1 week ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- Grype - v0.91.0 released (1 day ago)
- Syft - v1.22.0 released (1 day ago)
- Stereoscope - v0.1.2 released (1 day ago)
- Anchore Open Source Weekly Report - Week 13, 2025 (2 days ago)
- Grype is wrong about CVE-2024-37371 in libkrb5-3@1.20.1-2+deb12u2 (3 days ago)