• Skip to main content
  • Skip to secondary menu
  • Skip to footer

OSINT.org

Intelligence Matters

  • Sponsored Post
  • About
    • GDPR
  • Contact

Anchore Unveils New Open Source Tools For Automated DevSecOps Pipeline Security

October 6, 2020 By admin Leave a Comment

Anchore, Inc., the leading experts in policy-based workflow and compliance, is launching a collection of new open source tools for automating DevSecOps pipeline security and analysis. Syft and Grype are the first in a collection of tools designed for integration and performance. The tools analyze and scan container images and filesystems, allowing developers to enhance best practices within existing workflows and systems.

As cybersecurity breaches become more numerous and costly, traditional safeguarding tactics grow less effective. Incident response teams are often overwhelmed by having to constantly investigate the cause of previous breaches while developing new preventative measures as the pace of software delivery quickens. With Anchore developers have a unique opportunity to address problems before software is ever deployed and before an incident can occur.

“Our mission at Anchore is to give developers the tools they need to build security into their everyday tasks,” said Anchore CTO Daniel Nurmi. “That means they need to work seamlessly with a large collection of other tools and systems, providing instant results so developers can act immediately. Syft and Grype were designed for exactly that purpose, and are the first of many tools to come.”

Syft analyzes container images and filesystems to create a Software Bill of Materials (SBOM), a comprehensive record of operating system packages and language artifacts. Using Syft, developers can inspect the contents of new software components before deciding to use them and maintain a comprehensive record of the third-party software included in their projects. Syft generates SBOMs that conform to the CycloneDX specification, providing interoperability with a range of software supply chain management tools.

Grype scans container images and filesystems for known vulnerabilities, matching contents against Anchore Feed Service data compiled from multiple public data sources. Developers can use Grype to discover vulnerable components quickly inside projects as they are created and take the appropriate steps for remediation. The Visual Studio Code extension for Grype brings vulnerability scanning directly into the developer’s environment, rescanning projects regularly to watch for emerging vulnerabilities. Developers can easily trigger a Grype vulnerability scan of GitHub projects using the Anchore Container Scan GitHub Action.

“As an open source company, we do research and development in the open,” shared Anchore VP of Product Management Neil Levine. “In recent surveys, customers and community members agreed that security scanning can never be too fast and integration can never be too easy. We are looking forward to seeing how developers and DevOps teams use the tools while we focus on enhancing them with the policy features of our continuous compliance platform, Anchore Enterprise.”

Syft and Grype are available immediately at toolbox.anchore.io. The Visual Studio Code extension can be found in the Visual Studio Marketplace, and the GitHub Action can be found in the GitHub Marketplace. Contributions, feature requests, and issue reports are welcome at the GitHub projects for each tool.

For more information, visit Anchore.

About Anchore
Anchore, Inc., based in Santa Barbara, CA, was founded in 2016 by Saïd Ziouani and Daniel Nurmi to help organizations implement secure container-based workflows using Anchore Enterprise and Anchore Federal. With Anchore, DevSecOps teams establish policy-based approaches to container compliance without compromising velocity. Customers range from Fortune 100 companies to small- and mid-sized customers. Anchore is trusted by modern software development companies across the globe.

SOURCE Anchore

Home

Filed Under: Workflow

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • LILT Assist and the Push to Turn Localization Into an Autonomous Operating Layer
  • Tranquility AI and Fivecast Turn OSINT Into Real-Time Intelligence Workflows
  • Pre-Ceasefire Surge: Israel Accelerates Operations as U.S.-Led Ceasefire Push Gains Momentum
  • Tehran’s Long War Thesis: Endurance as Strategy
  • The Caspian Strike and the Message Beneath It
  • Understanding the Basij and the Significance of the Reported Strikes in Iran
  • Japan Hesitates on Hormuz Patrols as Global Shipping Security Debate Intensifies
  • Why Russia Benefits from Tension in the Strait of Hormuz
  • Cuba’s Regime Under Pressure as Its Allies Weaken
  • China’s Taiwan Air Patrols Resume — But the Real Signal May Be Inside the PLA

Media Partners

  • Analysis.org
  • Opinion.org
Memory Market Reality Check: Micron’s Drop Ripples Across the Sector
The Rise of China’s Hottest New Commodity: AI Tokens
The $1.6 Trillion Infrastructure Rebound That’s Quietly Rewiring Power, Data, and Control
The Day Geopolitics Repriced Everything
FedEx Signals a Logistics Cycle Turn — Growth Returns, but the Real Story Is Structural Reinvention
Iran’s Strategy in the Strait of Hormuz
Broadcom’s AI Semiconductor Revenue Surges Past $8.4 Billion, More Than Doubling in a Single Year
CoreWeave’s $5B Moment: Hypergrowth, Heavy Debt, and the Real Cost of Being the AI Cloud of Choice
NVIDIA’s Q4 FY2026 Was a Scale Event: $68.1B Quarter, $215.9B Year, and Guidance That Shrugged Off China
Tempus AI Q4 and Full-Year 2025: When Precision Medicine Starts Behaving Like a Platform
The Reckoning Europe Chose Not to Prepare For
The Trap They Built Themselves: Iran’s Strategic Self-Defeat
The Ministry of Unreality: How Trump’s Witch Hunts Against Vaccines and Wind Energy Are Breaking America
A Grotesque Reenactment: Trump Charges the Windmills, America Pays the Bill
Strategic Overreach and the Collapse of Iran’s Leverage
The Gulf Divide Is Ideological as Much as Strategic
The Mullahs Are Finished — And It’s Time to Say It Out Loud
Immortal Man (Peaky Blinders): Style, Superstition, and Character Collapse
Insolvency or Framing? A Critical Reading of the “U.S. Government is Insolvent” Argument
Iran’s Strategic Breakdown: When Survival Instinct Turns Into Escalation

Media Partners

  • Market Analysis
  • Market Research Media
Betting the Backbone: A Multi-Year Positioning on AMD, Broadcom, and Nvidia
Nvidia’s Groq 3 LPX: The $20B Bet That Could Define the Inference Era
Why Arm’s New AI Chip Changes the Rules of the Game
A Map Without Hormuz: Rewiring Global Oil Flows Through Fragmented Corridors
RoboForce’s $52 Million Raise Signals That Physical AI Is Moving From Demo Stage to Industrial Scale
The Hormuz Crisis: Winners and Losers in the Global Energy Shock
Zohran Mamdani’s Politics of Confiscation
Beyond Shipyards: Stephen Carmel’s Maritime Warning and the Hard Reality of Rebuilding an Oceanic System
Memory Crunch: Why Prices Are Surging and Why Making More Memory Isn’t Easy
The End of Accounting as We Knew It
Netflix Price Hikes, The Economics of Dominance in a Saturated Streaming Market
America’s Brands Keep Winning Even as America Itself Slips
Kioxia’s Storage Gambit: Flash Steps Into the AI Memory Hierarchy
Mamdani Strangling New York
The Rise of Faceless Creators: Picsart Launches Persona and Storyline for AI Character-Driven Content
Apple TV Arrives on The Roku Channel, Expanding the Streaming Platform Wars
Why Attraction-Grabbing Stations Win at Tech Events
Why Nvidia Let Go of Arm, and Why It Matters Now
When the Market Wants a Story, Not Numbers: Rethinking AMD’s Q4 Selloff
BBC and the Gaza War: How Disproportionate Attention Reshapes Reality

Copyright © 2022 OSINT.org

Technologies, Market Analysis & Market Research and Exclusive Domains