We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- Generating SBOMs for JavaScript Projects: A Developer’s Guide (4 days ago)
- Truth in IT: Keeping Your Code Shipshape with SBOMs! (6 days ago)
- The Developer’s Guide to SBOMs & Policy-as-Code (1 week ago)
- Contributing to Vulnerability Data: Making Security Better for Everyone (1 week ago)
- Software Supply Chain Transparency: Why SBOMs Are the Missing Piece in Your ConMon Strategy (2 weeks ago)
We discuss our open source tools on Discourse. Here are some recent topics:
- Anchore Open Source Weekly Report - Week 13, 2025 (1 day ago)
- Grype is wrong about CVE-2024-37371 in [email protected]+deb12u2 (2 days ago)
- Add OS related information on language based packages (1 week ago)
- Understanding Syft's Software Detection Mechanism and Architecture (1 week ago)
- Anchore Open Source Weekly Report - Week 12, 2025 (1 week ago)