We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype
We regularly write about what we're working on; here are some recent blog posts:
- Security Without Friction: How RepoFlow Created a DevSecOps Package Manager with Grype (5 days ago)
 - Beyond The CVE: Deep Container Analysis with Anchore (1 week ago)
 - Breaking the Vulnerability Management Cycle with Anchore and Echo (1 week ago)
 - Anchore Enterprise 5.22: OpenVEX, PURLs, and RHEL EUS Support (1 week ago)
 - Compliance Isn’t an Annual Ritual Anymore (2 weeks ago)
 
We discuss our open source tools on Discourse. Here are some recent topics:
- November 6 | Open Source Gardening | Live Stream (today)
 - Does grype fully handle the Trivy based SBOM vulnerability analysis? (1 day ago)
 - Does grype covers urls instead of version in npm? (2 days ago)
 - October 23rd 2025 | Open Source Gardening | Live Stream (4 days ago)
 - October 16th 2025 | Open Source Gardening | Live Stream (5 days ago)
 
