• Skip to main content
  • Skip to secondary menu
  • Skip to footer

OSINT.org

Intelligence Matters

  • Sponsored Post
  • About
    • GDPR
  • Contact

Anchore Unveils New Open Source Tools For Automated DevSecOps Pipeline Security

October 6, 2020 By admin Leave a Comment

Anchore, Inc., the leading experts in policy-based workflow and compliance, is launching a collection of new open source tools for automating DevSecOps pipeline security and analysis. Syft and Grype are the first in a collection of tools designed for integration and performance. The tools analyze and scan container images and filesystems, allowing developers to enhance best practices within existing workflows and systems.

As cybersecurity breaches become more numerous and costly, traditional safeguarding tactics grow less effective. Incident response teams are often overwhelmed by having to constantly investigate the cause of previous breaches while developing new preventative measures as the pace of software delivery quickens. With Anchore developers have a unique opportunity to address problems before software is ever deployed and before an incident can occur.

“Our mission at Anchore is to give developers the tools they need to build security into their everyday tasks,” said Anchore CTO Daniel Nurmi. “That means they need to work seamlessly with a large collection of other tools and systems, providing instant results so developers can act immediately. Syft and Grype were designed for exactly that purpose, and are the first of many tools to come.”

Syft analyzes container images and filesystems to create a Software Bill of Materials (SBOM), a comprehensive record of operating system packages and language artifacts. Using Syft, developers can inspect the contents of new software components before deciding to use them and maintain a comprehensive record of the third-party software included in their projects. Syft generates SBOMs that conform to the CycloneDX specification, providing interoperability with a range of software supply chain management tools.

Grype scans container images and filesystems for known vulnerabilities, matching contents against Anchore Feed Service data compiled from multiple public data sources. Developers can use Grype to discover vulnerable components quickly inside projects as they are created and take the appropriate steps for remediation. The Visual Studio Code extension for Grype brings vulnerability scanning directly into the developer’s environment, rescanning projects regularly to watch for emerging vulnerabilities. Developers can easily trigger a Grype vulnerability scan of GitHub projects using the Anchore Container Scan GitHub Action.

“As an open source company, we do research and development in the open,” shared Anchore VP of Product Management Neil Levine. “In recent surveys, customers and community members agreed that security scanning can never be too fast and integration can never be too easy. We are looking forward to seeing how developers and DevOps teams use the tools while we focus on enhancing them with the policy features of our continuous compliance platform, Anchore Enterprise.”

Syft and Grype are available immediately at toolbox.anchore.io. The Visual Studio Code extension can be found in the Visual Studio Marketplace, and the GitHub Action can be found in the GitHub Marketplace. Contributions, feature requests, and issue reports are welcome at the GitHub projects for each tool.

For more information, visit Anchore.

About Anchore
Anchore, Inc., based in Santa Barbara, CA, was founded in 2016 by Saïd Ziouani and Daniel Nurmi to help organizations implement secure container-based workflows using Anchore Enterprise and Anchore Federal. With Anchore, DevSecOps teams establish policy-based approaches to container compliance without compromising velocity. Customers range from Fortune 100 companies to small- and mid-sized customers. Anchore is trusted by modern software development companies across the globe.

SOURCE Anchore

Homepage – New

Filed Under: Workflow

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Footer

Recent Posts

  • Mahan Air Flight to Sanaa Points to Iran-Houthi Planning for a Bab el-Mandeb Blockade Scenario
  • Penguin Solutions Q3 FY26: The Margin Number Nobody’s Headline Mentioned
  • Palantir Expands Mexico Deal: GNP Seguros Becomes Its First Named Latin America Customer
  • DeepSeek Chip-Design Hiring Adds to the Custom Silicon Wave Pressuring Nvidia
  • Would Turkey Getting F-35s Actually Happen — And What Would It Mean for Israel
  • Iran Holds the Line on Hormuz While Trump Claims a Win the Market Isn’t Buying
  • Rheinmetall and Vantor Plan a Sovereign Spatial Intelligence Joint Venture for Germany
  • How SOCMINT Evolved: From API Access to Manual Tradecraft
  • The Ceasefire Is a Pause, Not a Peace. The War Should Resume.
  • Kalshi Raises $1 Billion at $22 Billion Valuation

Media Partners

  • Analysis.org
  • Opinion.org
  • Policymaker.net
Micron’s $500 Million GlobalWafers Financing Points to a New Bottleneck
META Compute, Samsung, SK Hynix: Where AI Infrastructure Investors Think the Margin Actually Sits
AMD Acquired MEXT to Make Flash Behave Like DRAM. It Eases the Memory Crunch Without Threatening Micron or SanDisk.
The Memory Shortage Is an Existential Event for Small Electronics Makers, Not Just a Margin Hit
The Manic Phase Is Real. The Crash Date Is Not.
Oracle’s $95 Billion Capex Guide Meets a 6.5% PPI: Today’s Session Is the Test for Nvidia, AMD, and the AI Chip Trade
PPI May 2026: Producer Prices Surge 1.1% as Iran War Energy Shock Hits the Pipeline, Goods Inflation Sets a Record
June 22 Is the Date That Changes Everything for MRVL Shareholders
SpaceX (SPCX) IPO: Why Facebook’s 2012 Debut Is the Warning Label on the Largest IPO in History
SK Hynix Eyes August US Listing: A $14 Billion ADR Raise Lands in the Middle of the AI Liquidity Pipeline
Trump’s $1.4 Billion Crypto Year: A Disclosure That Doubles as a Conflict-of-Interest Ledger
JD Vance and the Grifter Generation: No Allies, No Principles, Only Power
Trump’s Iran Deal: The U-Turn From Unconditional Surrender to All Carrots, No Stick
Trump’s Iranian Deal Delusion Syndrome: Why the Regime Cannot Change Without Force From Outside and Within
The Deal That Won’t Hold — And Why That May Be Correct
Washington’s Iran Capitulation Will Cost More Than the Deal Is Worth
Trump’s Indecisiveness Has Emboldened Iran. Now Trump Is Cornered.
The UAE’s OPEC Exit Is a Middle East Realignment, Not an Oil Story
Hormuz Is a Message to Beijing and Moscow
Ammunition Drain: How the Iran Campaign May Be Weakening Taiwan’s Deterrence
Trump's 20% Hormuz Toll Is Fifteen Times the Iranian Fee He Went to War to Stop
Trump's Real Target With Erdogan Is the Hormuz Bypass, Not the F-35
Mamdani's Slate Is Capturing Congress Through Primaries Almost No One Votes In
Starmer Falls, Burnham Rises, and Britain Changes Prime Minister Without an Election
Hormuz Reopens and Equities Rotate: Energy Sells Off, Tech Leads, North Asia Soars
The Islamabad Agreement: Trump Cancels His Own Strikes, Pays Iran for the Privilege, and Calls It a Deal
Film Star Vijay Forms Government in Tamil Nadu: The Celebrity-to-Power Trajectory Completes
The Gulf Realignment Washington Missed
Seven Million and Counting: Britain's Managed Demographic Replacement
UK Taxpayers Are Funding £4 Billion a Year in Student Loans for Foreign Nationals

Media Partners

  • Market Analysis
  • Market Research Media
  • Cybersecurity Market
Enterprise Money Is Leaving Old School IBM for AI Infrastructure Companies
Why EU Tech Is Falling Behind the US: A Structural Diagnosis, Not a Cultural One
The HyperLight Threat to Coherent and Lumentum Ends Where Indium Phosphide Begins
SpaceX IPO (SPCX): A $1.75 Trillion Valuation Built on Selling 4% of the Company to People Who Watch Rocket Launches
What a Trillion-Dollar Cloudflare Actually Requires
The Repricing and the Drain: How SpaceX, OpenAI, and Anthropic Rewire the Index
Quantum Computing Equities: Market Segment Memo
Quantum Computing Stocks Face Violent Selloff the Moment Markets Reopen Tuesday
The $2.6 Trillion Signal: What Gartner’s AI Spending Forecast Actually Tells You
The Productivity Is Already Here. The Bubble Narrative Is Not.
Getty Images Kills the $3.7 Billion Shutterstock Merger Rather Than Sell the Editorial Business the UK Demanded
Fox’s $22B Roku Deal: 4.6x Sales, Paid in 1.5x Stock
Tuesday Open: AI Earnings Engine Holds the Line as Iran Overhang Fades to Noise
China’s U.S. Treasury Holdings: The Great Repositioning (2021–2025)
Infographic: Why the 2025 CIPA Data Proves the APS-C Renaissance is Real
How WiFi Changed Media
Canva Acquires Simtheory and Ortto to Build End-to-End Work Platform
Netflix Price Hikes, The Economics of Dominance in a Saturated Streaming Market
America’s Brands Keep Winning Even as America Itself Slips
Kioxia’s Storage Gambit: Flash Steps Into the AI Memory Hierarchy
Cybersecurity Stocks Rally as IBM CEO Flags Cyber Fears as a Top Customer Priority
Trump Administration Launches “Gold Eagle” Federal Clearinghouse for AI Cyber Threat Sharing
JadePuffer: Researchers Document the First Fully Autonomous AI Ransomware Attack
Aikido Acquires Root for a Reported $70 Million to Patch Open Source Without Forcing Upgrades
The three-week freeze on Anthropic’s most capable models is over
Miasma Supply Chain Worm Jumps to Go and Now Executes Inside AI Coding Assistants
Two-Factor Authentication Bypass: Attackers Brute-Force 2FA Systems, Gaining Access to Enterprise Accounts
France’s Tchap Government Messaging Breach Signals Weak Oversight of Encrypted State Communications
OpenSSL CVE-2026-45447: Heap Use-After-Free in PKCS#7 Verification Enables S/MIME RCE, Discovered With AI
Microsoft Patch Tuesday June 2026: Record 200+ Vulnerabilities in Single Release, Three Pre-Disclosure Zero-Days

Copyright © 2026 OSINT.org

Media Partners: k4i · OPINT · Referently · Hormuz · Taiwan Strait