• Skip to main content
  • Skip to secondary menu
  • Skip to footer

OSINT.org

Intelligence Matters

  • Sponsored Post
    • Make a Contribution
  • Market Intelligence
    • Technologies
    • Events
  • Domain Intelligence
  • About
    • GDPR
  • Contact

Anchore Unveils New Open Source Tools For Automated DevSecOps Pipeline Security

October 6, 2020 By admin Leave a Comment

Anchore, Inc., the leading experts in policy-based workflow and compliance, is launching a collection of new open source tools for automating DevSecOps pipeline security and analysis. Syft and Grype are the first in a collection of tools designed for integration and performance. The tools analyze and scan container images and filesystems, allowing developers to enhance best practices within existing workflows and systems.

As cybersecurity breaches become more numerous and costly, traditional safeguarding tactics grow less effective. Incident response teams are often overwhelmed by having to constantly investigate the cause of previous breaches while developing new preventative measures as the pace of software delivery quickens. With Anchore developers have a unique opportunity to address problems before software is ever deployed and before an incident can occur.

“Our mission at Anchore is to give developers the tools they need to build security into their everyday tasks,” said Anchore CTO Daniel Nurmi. “That means they need to work seamlessly with a large collection of other tools and systems, providing instant results so developers can act immediately. Syft and Grype were designed for exactly that purpose, and are the first of many tools to come.”

Syft analyzes container images and filesystems to create a Software Bill of Materials (SBOM), a comprehensive record of operating system packages and language artifacts. Using Syft, developers can inspect the contents of new software components before deciding to use them and maintain a comprehensive record of the third-party software included in their projects. Syft generates SBOMs that conform to the CycloneDX specification, providing interoperability with a range of software supply chain management tools.

Grype scans container images and filesystems for known vulnerabilities, matching contents against Anchore Feed Service data compiled from multiple public data sources. Developers can use Grype to discover vulnerable components quickly inside projects as they are created and take the appropriate steps for remediation. The Visual Studio Code extension for Grype brings vulnerability scanning directly into the developer’s environment, rescanning projects regularly to watch for emerging vulnerabilities. Developers can easily trigger a Grype vulnerability scan of GitHub projects using the Anchore Container Scan GitHub Action.

“As an open source company, we do research and development in the open,” shared Anchore VP of Product Management Neil Levine. “In recent surveys, customers and community members agreed that security scanning can never be too fast and integration can never be too easy. We are looking forward to seeing how developers and DevOps teams use the tools while we focus on enhancing them with the policy features of our continuous compliance platform, Anchore Enterprise.”

Syft and Grype are available immediately at toolbox.anchore.io. The Visual Studio Code extension can be found in the Visual Studio Marketplace, and the GitHub Action can be found in the GitHub Marketplace. Contributions, feature requests, and issue reports are welcome at the GitHub projects for each tool.

For more information, visit Anchore.

About Anchore
Anchore, Inc., based in Santa Barbara, CA, was founded in 2016 by Saïd Ziouani and Daniel Nurmi to help organizations implement secure container-based workflows using Anchore Enterprise and Anchore Federal. With Anchore, DevSecOps teams establish policy-based approaches to container compliance without compromising velocity. Customers range from Fortune 100 companies to small- and mid-sized customers. Anchore is trusted by modern software development companies across the globe.

SOURCE Anchore

Home

Filed Under: Workflow

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • Cognyte Wins $5M Contract to Power Tactical SIGINT for Major EMEA Military Intelligence Agency
  • Huawei Africa Night 2025: Vision for “New Africa” or Blueprint for Dependency?
  • Longeye Raises $5M to Bring AI-Powered Investigations to Law Enforcement
  • Jared Kushner’s Bid for Electronic Arts: Soft Power, FIFA Politics, and the Israel Question
  • U.S. Preparations to Overthrow the Maduro Regime
  • Qatar Buys Influence Through AI Infrastructure: QIA–Blue Owl $3B Data Center Deal
  • Israel’s Strategic Position Beyond Public Opinion
  • Poland’s Calculated Bet: Bolstering Ukraine’s Long-Range Strike Capabilities
  • Is the U.S. Actually Planning an Invasion or Coup in Venezuela?
  • Tadaweb Secures $20M to Expand Human-Centric OSINT Platform

Media Partners

  • Analysis.org
  • Opinion.org
AMD’s Pullback Looks More Like a Pause — And Nvidia’s Beat May Be the Turning Point
PayPal Pay in 4 Arrives in Canada for the Holiday Rush
NuScale Power: The SMR Bet Moves From Concept to Commercial Deployment
The Waiting Game at the Bank of England
Maersk Q3 2025: The Quiet Rebuild of a Global Trade Powerhouse
Tempus AI: Scaling Into an Inflection Point
Palantir’s Explosive Q3: When “AI Leverage” Becomes a Revenue Machine
Nexperia, China, Netherlands: A Semiconductor Flashpoint in Europe’s Geopolitical Balancing Act
Jensen Huang and the AI Virtuous Cycle: The Economics of Infinite Acceleration
Cloudflare’s Q3 Beat, Reacceleration, and the Quiet Cash Engine Powering the “Connectivity Cloud”
Europe’s Telecom Awakening — The Huawei Breakup Feels a Lot Like the Russian Gas Divorce
Woke Journalism as a Camouflaged Form of Anarchism
Israel Surrounded by Failed States
It Was Qatar All Along: Qatar’s Network of Influence and the Long Campaign Against Israel and the West
Photo of the Day: Pro-Palestinian Mobs Harassing European Cities
Hamas’s “Yes” That Really Means “No”
Spain’s Boom Is a Corruption-Fueled Illusion
Europe to Erdogan: Don’t Teach Us How to Eat
Europe’s Imported Illusion: He must be an engineer
Erdogan’s Possible Collapse

Media Partners

  • Market Analysis
  • Market Research Media
U.S. Housing Market Turns Sharply in Favor of Buyers, But Affordability Remains a Wall
Europe’s Turning Point: Why Cutting Out Chinese Tech Isn’t Just Necessary — It’s Long Overdue
Nvidia Q3 FY2026 Earnings: Still the Center of Gravity in the AI Super-Cycle
Ghost Kitchens as Infrastructure: The Shift from Restaurants to Intelligent Food Networks
Why are AI stocks falling if Anthropic is buying $30B of Azure capacity?
Sony’s Spark, and the Strange Quiet That Followed
Celero Communications Secures $140M to Push the Optical Frontier of AI Infrastructure
NTT R&D Forum 2025, Tokyo — When Quantum Stops Being Theory
IIFES 2025, November 19–21, 2025, Tokyo Big Sight
China Played Trump, Again: Soybeans, Strategy, and Leverage
AppCoding.com — A Clear, Flexible Identity at the Center of the Software-Everywhere Economy
APIcoding.com — A Digital Asset Aligned With the Infrastructure of the Modern Software Economy
NewsInstances.com — A Digital Identity Built for Event-Driven Media and AI-Generated Reporting
Marketing Content Creation Services in 2025
Visual Storytelling and the Rise of Gamma in the AI Productivity Stack
The Trade Desk: Durable Growth, Wider Moats, and a Faster Flywheel on the Open Internet
Expedia Group: Reacceleration in Core Travel Demand and Strong B2B Tailwinds Push Results Above Expectations
BuzzFeed, Inc. – Q3 2025 Analytical Report
The Rise of the Micro-Series Phenomenon
Canva’s Creative Operating System: A Strategic Shockwave for the Design Industry

Copyright © 2022 OSINT.org

Technologies, Market Analysis & Market Research and Exclusive Domains