Anchore
banner
anchore.com
Anchore
@anchore.com
Securing and managing the software supply chain. Proud parent of @syftproject.bsky.social and @grypeproject.bsky.social
The OWASP Top 10 just added supply chain security.

But as @josh.bressers.name writes, just being on the list changes nothing. We don't solve systemic problems by buying a tool or just talking about them.
... https://anchore.com/blog/supply-chain-security-made-the-owasp-top-ten-this-changes-nothing/
November 22, 2025 at 4:50 PM
⚠️ The Timing Gap: By the time you scan a container image, package installation scripts have already run with full privileges.

If that package was malicious, it's already too late.

Stop the threat at ... https://anchore.com/blog/the-unseen-threat-why-you-need-to-scan-your-source-code-repositories/
November 21, 2025 at 6:13 PM
**Last Chance! We start in ONE HOUR!** ⏳Neil Levine and Nurit from Echo are ready to show you the proactive path to container security.
Get the playbook for eliminating vulnerabilities at the source and... https://go.anchore.com/anchore-and-echo.html
#hardenedimages #ContainerSecurity #Anchore #Echo
November 21, 2025 at 2:50 AM
🚨 **Final Call: Just 24 Hours Until Our Live Demo!** 🚨
Tomorrow, us and our friends at Echo are showing you how to quit the vulnerability patching cycle for good. If your team is buried under a backlog of cont... https://go.anchore.com/anchore-and-echo.html #DevSecOps #ContainerSecurity #FinalCall
November 20, 2025 at 3:59 AM
The cavalry isn't coming to save us, we are the cavalry."

A powerful call to action from @josh.bressers.name on the new OWASP #3.

Stop waiting for a tool to solve supply chain security. We h... https://anchore.com/blog/supply-chain-security-made-the-owasp-top-ten-this-changes-nothing/

#OWASPTop10
November 19, 2025 at 10:39 PM
Container scanning checks if your ingredients are fresh. Source code scanning checks if your recipe is poisoned. 🍲☠️

If you aren't doing both, you're only seeing half the risk.

Read why you need to s... https://anchore.com/blog/the-unseen-threat-why-you-need-to-scan-your-source-code-repositories/
November 19, 2025 at 5:41 AM
With the EU's Cyber Resilience Act, #SoftwareTransparency isn't optional. It's a global mandate.

We're thrilled to announce #SBOM pioneer @allanfriedman.bsky.social is joining the Anchore board to help nav... https://anchore.com/blog/anchore-welcomes-sbom-pioneer-dr-allan-friedman-as-board-advisor/
November 17, 2025 at 6:16 PM
The new OWASP entry isn't "Software Supply Chain Failures."

It's "'Random software I found in the couch cushions that I don't understand.'"

A hilarious, and painfully true, take from @josh.bressers.name ... https://anchore.com/blog/supply-chain-security-made-the-owasp-top-ten-this-changes-nothing/
November 16, 2025 at 7:57 PM
Vulnerability scanners → what's there
VEX → what it means

Anchore Enterprise 5.23 adds CycloneDX VEX/VDR support. Software publishers can now share authoritative vulnerability context across their entire supply chain.

https://anchore.com/blog/anchore-enterprise-5-23-cyclonedx-vex-and-vdr-support/
November 15, 2025 at 11:50 PM
We've partnered with @allanfriedman.bsky.social for years on "SBOM-a-Rama" & VEX. Today, we're thrilled to announce the primary architect of the #SBOM movement is joining the Anchore Board of Advisors.

A s... https://anchore.com/blog/anchore-welcomes-sbom-pioneer-dr-allan-friedman-as-board-advisor/
November 14, 2025 at 9:57 PM
The biggest fear in B2B sales right now? An auditor saying, "You didn't do the reasonable thing... what everybody else is doing."

The "reasonable" standard is being... https://anchore.com/blog/the-eu-cra-compliance-cascade-why-your-customers-and-acquirers-now-demand-a-verifiable-devsecops-pipeline/
November 14, 2025 at 8:22 PM
If you write code, buy software, or run apps (so... everyone in 2025), everything you know about software development is changing.

The "move fast and break things" era is now "move fast and document everything."

What's your compli... https://anchore.com/blog/navigating-the-new-compliance-frontier/
November 14, 2025 at 6:11 PM
The OWASP list just added Software Supply Chain Failures. But does the list solve problems?

Our VP of Security, @josh.bressers.name, argues "we re-rank it every year but never solve anything."

Read his n... https://anchore.com/blog/supply-chain-security-made-the-owasp-top-ten-this-changes-nothing/
November 14, 2025 at 1:48 AM
Is your compliance process a "speed bump" for devs? It needs to be a "navigation system."

Our webinar explores how CompOps uses automated policies to guide develope... https://anchore.com/blog/the-eu-cra-compliance-cascade-why-your-customers-and-acquirers-now-demand-a-verifiable-devsecops-pipeline/
November 13, 2025 at 2:23 AM
Syft & Grype have hit 40 million downloads!
A massive thank you to the open source community for trusting us to secure their software supply chains.
#OpenSource #SBOM #DevSecOps
https://anchore.com/opensource
November 12, 2025 at 10:25 PM
Anchor's Grype + Echo OS base images = A better way to build. 🔒
Ready to stop endless patching? Join Anchore and Echo to see how we tackle container vulnerabilities at the root cause.
We'll demo the power of st... https://go.anchore.com/anchore-and-echo.html
#ContainerSecurity #DevSecOps #TechDemo
November 12, 2025 at 8:34 PM
HUGE NEWS! 📣

The "father of SBOM," @allanfriedman.bsky.social, is joining Anchore as a Board Advisor!

We sat down with him to discuss the future of #SoftwareSupplyChainSecurity and what comes after SBOM.... https://anchore.com/blog/anchore-welcomes-sbom-pioneer-dr-allan-friedman-as-board-advisor/
November 12, 2025 at 3:01 AM
Your security team has explained the same "vulnerability" to 5 different customers this month.

VEX solves this: document vulnerability status once, export in OpenVEX or CycloneDX format.

Anchore Enterprise 5.23 supp...
https://anchore.com/blog/anchore-enterprise-5-23-cyclonedx-vex-and-vdr-support/
November 11, 2025 at 4:42 AM
Your GenAI Risk Questions, Answered by the Experts.
Join Nathan Parker, Kathryn Carlson, Josh Bressers, and more for the deep dive int... https://executiveitforums.org/11011-cpe-generative-ai-in-risk-and-compliance-insights-from-the-2025-industry-report
#GenAIRisk #ComplianceTech #ExpertPanel #Nov12
November 10, 2025 at 6:27 PM
Forget waiting for a regulator.

The "compliance cascade" is here. Your biggest customer is about to become your strictest auditor and will contractually force CRA r... https://anchore.com/blog/the-eu-cra-compliance-cascade-why-your-customers-and-acquirers-now-demand-a-verifiable-devsecops-pipeline/
November 9, 2025 at 4:12 AM
Anchore Enterprise 5.23: Complete VEX support with CycloneDX

✅ OpenVEX (5.22)
✅ CycloneDX VEX (5.23)
✅ CycloneDX VDR 5.23)

Annotate vulnerabilities once, export in either format. Your customers get context in the st...
https://anchore.com/blog/anchore-enterprise-5-23-cyclonedx-vex-and-vdr-support/
November 8, 2025 at 5:15 AM
"Security tools are notorious for adding back the complexity they're meant to protect against."

@RepoFlow_io flipped that script—integrating Anchore's @SyftProject + @GrypeProject for ... https://anchore.com/blog/security-without-friction-how-repoflow-created-a-devsecops-package-manager-with-grype/
November 7, 2025 at 8:21 PM
Zero CVEs ≠ Zero Risk.

Misconfigurations & leaked secrets can take down an image faster than any exploit.

Anchore helps teams catch both.

By @JoshSopuru → https://anchore.com/blog/beyond-the-cve-deep-container-analysis-with-anchore/

#SBOM #ContainerSecurity #PolicyAsCode #SoftwareSupplyChain
November 6, 2025 at 6:37 PM
Stop seeing the EU CRA as a "regulatory burden." It's a "competitive differentiator."

The auditors who matter aren't regulators. They're your customers' procurement... https://anchore.com/blog/the-eu-cra-compliance-cascade-why-your-customers-and-acquirers-now-demand-a-verifiable-devsecops-pipeline/
November 6, 2025 at 3:22 AM
Tired of the never-ending stream of container vulnerabilities? 😫
Stop reacting and start eliminating them at the source!
Join Anchore and Echo for a live demo on Proactive Security. Learn how starting with Ec... https://go.anchore.com/anchore-and-echo.html
#DevSecOps #ContainerSecurity #CloudNative
November 5, 2025 at 3:11 AM