• Skip to main content
  • Skip to secondary menu
  • Skip to footer

OSINT.org

Intelligence Matters

  • Sponsored Post
  • About
    • GDPR
  • Contact

Anchore Unveils New Open Source Tools For Automated DevSecOps Pipeline Security

October 6, 2020 By admin Leave a Comment

Anchore, Inc., the leading experts in policy-based workflow and compliance, is launching a collection of new open source tools for automating DevSecOps pipeline security and analysis. Syft and Grype are the first in a collection of tools designed for integration and performance. The tools analyze and scan container images and filesystems, allowing developers to enhance best practices within existing workflows and systems.

As cybersecurity breaches become more numerous and costly, traditional safeguarding tactics grow less effective. Incident response teams are often overwhelmed by having to constantly investigate the cause of previous breaches while developing new preventative measures as the pace of software delivery quickens. With Anchore developers have a unique opportunity to address problems before software is ever deployed and before an incident can occur.

“Our mission at Anchore is to give developers the tools they need to build security into their everyday tasks,” said Anchore CTO Daniel Nurmi. “That means they need to work seamlessly with a large collection of other tools and systems, providing instant results so developers can act immediately. Syft and Grype were designed for exactly that purpose, and are the first of many tools to come.”

Syft analyzes container images and filesystems to create a Software Bill of Materials (SBOM), a comprehensive record of operating system packages and language artifacts. Using Syft, developers can inspect the contents of new software components before deciding to use them and maintain a comprehensive record of the third-party software included in their projects. Syft generates SBOMs that conform to the CycloneDX specification, providing interoperability with a range of software supply chain management tools.

Grype scans container images and filesystems for known vulnerabilities, matching contents against Anchore Feed Service data compiled from multiple public data sources. Developers can use Grype to discover vulnerable components quickly inside projects as they are created and take the appropriate steps for remediation. The Visual Studio Code extension for Grype brings vulnerability scanning directly into the developer’s environment, rescanning projects regularly to watch for emerging vulnerabilities. Developers can easily trigger a Grype vulnerability scan of GitHub projects using the Anchore Container Scan GitHub Action.

“As an open source company, we do research and development in the open,” shared Anchore VP of Product Management Neil Levine. “In recent surveys, customers and community members agreed that security scanning can never be too fast and integration can never be too easy. We are looking forward to seeing how developers and DevOps teams use the tools while we focus on enhancing them with the policy features of our continuous compliance platform, Anchore Enterprise.”

Syft and Grype are available immediately at toolbox.anchore.io. The Visual Studio Code extension can be found in the Visual Studio Marketplace, and the GitHub Action can be found in the GitHub Marketplace. Contributions, feature requests, and issue reports are welcome at the GitHub projects for each tool.

For more information, visit Anchore.

About Anchore
Anchore, Inc., based in Santa Barbara, CA, was founded in 2016 by Saïd Ziouani and Daniel Nurmi to help organizations implement secure container-based workflows using Anchore Enterprise and Anchore Federal. With Anchore, DevSecOps teams establish policy-based approaches to container compliance without compromising velocity. Customers range from Fortune 100 companies to small- and mid-sized customers. Anchore is trusted by modern software development companies across the globe.

SOURCE Anchore

Home

Filed Under: Workflow

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • CentralSquare Technologies Acquires FirstTwo to Advance Real-Time Intelligence for First Responders
  • IMINT Brief: Virgin Galactic–LLNL High-Altitude Sensor Collaboration
  • Palantir Renews DGSI Contract, 3 Years, France
  • Global OSINT SitRep — War Maps, Shadow Fleets, Deepfakes, and the New Intelligence Battleground
  • OSINT Watch: A Quick Sweep Through the Latest Open-Source Intelligence Headlines
  • How AI-Driven Commerce Redefined Holiday Shopping
  • The Green Boxes That Could Tip a Global Power Balance
  • Antithesis Raises $105M to Push Deterministic Simulation Into the Mainstream
  • BlighterNexus Track: Real-Time Tracking Gets a Smarter Edge
  • Feasibly, Launch Day — AI Meets Real Estate Feasibility

Media Partners

  • Analysis.org
  • Opinion.org
Cisco Is Not in a Breakthrough
Why Broadcom Is Slipping in Pre-Market Trading Today
Oracle’s Post-Earnings Selloff: What’s Really Behind the 10% Pre-Market Drop
AVAV’s Valuation Shift: From Niche UAV Supplier to Scaled Defense Systems Integrator
Adobe Buyback Momentum Fuels a Sharp Afternoon Rally
Cross-Border Private Credit Expected to Surge, but Operational Risks Loom
Salesforce Q3 FY26: A Strong AI-Driven Quarter With Big ARR Gains — And A Market Ready To Debate The Next Leg Up
Snowflake Q3 FY26: Solid AI Momentum, Healthier Margins — And A Market Struggling To Reprice The Story
Why the Suez Canal Emptied: Security Shock First, Economy Second
Broadcom’s Slide and the Shift in Market Expectations
How a Quack Ended Up Steering National Health — And Why the Hepatitis B Rollback Is a Dangerous Farce
Europe’s Telecom Awakening — The Huawei Breakup Feels a Lot Like the Russian Gas Divorce
Woke Journalism as a Camouflaged Form of Anarchism
Israel Surrounded by Failed States
It Was Qatar All Along: Qatar’s Network of Influence and the Long Campaign Against Israel and the West
Photo of the Day: Pro-Palestinian Mobs Harassing European Cities
Hamas’s “Yes” That Really Means “No”
Spain’s Boom Is a Corruption-Fueled Illusion
Europe to Erdogan: Don’t Teach Us How to Eat
Europe’s Imported Illusion: He must be an engineer

Media Partners

  • Market Analysis
  • Market Research Media
U.S. Tech Employment Slows as Hiring Cools and AI Reshapes Demand
Semiconductor Equipment Boom, 2025–2027, Global Manufacturing Outlook
ServiceNow Sharpens Its Competitive Edge by Making Moveworks the Front Line of the Enterprise
NVIDIA Acquires SchedMD: How Owning the Brain of the Cluster Sharpens NVIDIA’s Competitive Edge
Cloudflare Year in Review 2025: How the Internet Quietly Rewired Itself
The $250 Billion Stablecoin Market: Who Uses It, Why It Exists, and Where the Growth Actually Comes From
Will It Save Intel? The $1.6B SambaNova Question
Crisp’s $26M Series B1 Shows Why Vertical AI Is Pulling Ahead
Europe’s Spectrum Trap: How Smarter Policy Could Unlock a €75 Billion 5G Boost
Airwallex’s $330M Series G: The New Gravity Center of Borderless Finance
PlayStation and the Quiet Power Center of a $200 Billion Gaming Industry
Adobe FY2025: AI Pulls the Levers, Cash Flow Leads the Story
Canva’s 2026 Creative Shift and the Rise of Imperfect-by-Design
fal Raises $140M Series D: Scaling the Core Infrastructure for Real-Time Generative Media
Gaming’s Next Expansion Wave, 2026–2030
Morphography — A Visual Language for the Next Era of AI
Netflix’s $83B Grab for Warner Bros. & HBO: A Tectonic Shift in Global Media
Clipbook Raises $3.3M Seed Round — And the PR World Just Got a Warning Shot
BrandsToShop.com — the right domain to have for Cyber Monday, Black Friday and every loud shopping season ahead
PressEspresso.com

Copyright © 2022 OSINT.org

Technologies, Market Analysis & Market Research and Exclusive Domains