Remote
anchore
@anchore@mstdn.business
Securing and managing the software supply chain. Proud parent of @syft@fosstodon.org and @grype@fosstodon.org
72 Followers
21 Following
50 Posts
Joined June 13, 2024
Built on 30M+ download open source tools (Syft & Grype) 🔧
Community-proven, enterprise-hardened 💪
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Open post
The problem with legacy SCAP tools? They trust the file system too much.
We grabbed this clip from our session with MITRE because it perfectly explains the shift to "Active Testing."
It's not enough to verify sshd_config exists. You have to query the daemon to see what it's actually enforcing.
See how we handled this in RHEL 9 & K8s: https://go.anchore.com/webinar-stig-in-action-with-mitre/
1
0
0
0
Open post
Teams that crack cATO ship mission software in minutes, not months. That's the edge Operation Stormbreaker built.
See how, July 29 with USMC MCCS, Raven Solutions, and Anchore.
https://go.anchore.com/architecting-a-DoD-software-factory.html
0
0
0
0
Open post
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
0
0
0
0
Open post
Built on 30M+ download open source tools (Syft & Grype) 🔧
Community-proven, enterprise-hardened 💪
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
0
0
0
0
Open post
"Bring Your Own SBOM" sounds simple...
Until you try to manage thousands of them 📊
Scale is everything 📈
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
0
0
0
0
Open post
Mitigate vulnerability noise. EU CRA incident reporting starts in 2026. You can't report what you cannot see. Stop manual triage & deploy continuous monitoring to accelerate remediation. Enforce policy gates to stay compliant by default & ship secure software faster. https://anchore.com/blog/eu-cra-vulnerability-management/
0
0
0
0
Open post
Shift-left compliance checking ⬅️
Catch violations before deployment, not during audits 🛡️
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
0
0
0
0
Open post
Onboarding a new team into Anchore Enterprise usually means clicking through account creation, user setup, and RBAC grants by hand. All of it is available via the API instead. Here's the script that does it end to end: https://anchore.com/blog/automating-admin-tasks-via-anchore-enterprise-api/
0
0
0
0
Open post
Your MCP server might be the weakest link—here's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
#MCP #SoftwareSupplyChain #ContainerSecurity #DevSecOps
0
0
0
0
Open post
A critical CVE in code that never runs trips the same alert as one in an exposed path. Severity scores can't tell the difference. VEX can.
New post by a guest author on operationalizing VEX in container pipelines: https://anchore.com/blog/operationalizing-vex-in-container-security-pipelines
0
0
0
0
Open post
We start in 1 hour.
Operation Stormbreaker's cATO architecture, live with USMC MCCS, Raven Solutions, and Anchore.
Join: https://go.anchore.com/architecting-a-DoD-software-factory.html
0
0
0
0
Open post
MCP is having a moment. @josh.bressers.name wanted to know: what are we actually shipping?
9,000 vulns
263 critical findings
36K+ NPM packages
Outdated base images
Not fear-mongering—just data-driven reality. Read his analysis: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
#MCP #ContainerSecurity
0
0
0
0
Open post
"The format doesn't really matter... It's really about the content."
We hosted @stevespringett, Chair of the CycloneDX WG, to discuss why the industry needs to stop fighting format wars and start focusing on data utility.
Read the 4 lessons: https://anchore.com/blog/4-lessons-on-future-of-software-transparency-with-steve-springett/
0
0
0
0
Open post
SBOMs are essential for "software archaeology." What did your build environment look like six months ago? Which past releases might be affected by a new vulnerability? This on-demand webinar explains why preserving lightweight SBOMs can answer these questions and provide critical historical context. #SBOM #Security #AppSec #DevSecOps
✅ See the power of historical SBOM data in action. Watch our expert webinar now: https://go.anchore.com/rapid-incident-response-with-sboms/
0
0
0
0
Open post
Anchore SBOM Score = CVSS + EPSS + KEV status 📊
Because not all vulnerabilities are created equal ⚠️
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
0
0
0
0
Open post
Supply chain attacks ↗️ 742% in 2023
Your traditional security stack wasn't built for this fight.
SBOM-first architecture changes everything ⚡
https://anchore.com/platform/
#SoftwareSupplyChain #SBOM #CyberSecurity
0
0
0
0
Open post
⚠️ Root user running
⚠️ Secrets in plain text
⚠️ Missing SBOM
Each one maps to a specific NIST 800-171 control your CMMC audit will check. The Anchore Enterprise CMMC Policy Pack automates all of it. https://anchore.com/blog/how-to-automate-cmmc-compliance-for-containers-sboms/
0
0
0
0
Open post
STIG scanning tools historically struggle with distroless images because they require an in-container shell. That gap is closed. Anchore Enterprise now evaluates STIG controls on shell-less @chainguard_dev images directly at the image layer. https://anchore.com/blog/stig-compliance-chainguard-images-now-supported/
0
0
0
0
Open post
EU CRA non-compliance: fines up to €15M or 2.5% of global turnover. Plus national authorities can ban your products from the EU market.
First deadline is September 11, 2026 — 24-hour exploit reporting.
Here's what you need to build before then. https://anchore.com/blog/the-eu-cra-reporting-deadline-heres-what-you-need/
0
0
0
0
Open post
VEX gives you the exploitability signal. Turning it into a consistent policy decision across pipelines is the hard part.
Guest author, Devashri Datta, proposes a structured interpretation layer to bridge the two: https://anchore.com/blog/operationalizing-vex-in-container-security-pipelines
0
0
0
0
Open post
@joshbressers: "If you can't search your past builds, you can't bound your blast radius. SBOMs turn a frantic morning into a simple query."
His zero-day incident response story from inside Anchore's response to the NPM supply chain attack:
https://anchore.com/blog/a-zero-day-incident-response-story-from-the-watchers-on-the-wall/
0
0
0
0
Open post
SPDX or CycloneDX — pick one. Using both creates friction, not coverage. That's one of 6 phases in our EU CRA Software Supply Chain Compliance Checklist. Download now → https://anchore.com/white-papers/eu-cra-software-supply-chain-checklist/
0
0
0
0
Open post
Manual security creates a visibility crisis. You can't secure what you can't see. 📉
Step 1: Generate a baseline SBOM instantly to stop accumulating operational debt.
Watch the full on-demand webinar for automating and scaling the rest: https://go.anchore.com/automate-generate-manage-sboms/
0
0
0
0
Open post
EU CRA's 24-hour vulnerability reporting requirement: September 11, 2026.
That's 45 days to have automated KEV enrichment, alerting, and notification templates in production.
We published a phased compliance checklist + a white paper on the full mandate. Both free. https://anchore.com/blog/the-eu-cra-reporting-deadline-heres-what-you-need/
0
0
0
0
Open post
🚀 New hardened container companies are launching constantly.
The reason isn't compliance mandates—it's practical necessity.
When scanners got accurate, the vulnerability problem became impossible to ignore. Hardened images are the efficient solution.
https://anchore.com/blog/hardened-images-are-here-to-stay/
0
0
0
0
Open post
"Fixed: 12. Introduced: 2. Persisting: 34, 8 with fixes available."
That's progress you can measure. Ben Lang shows how to get there with the Anchore Enterprise API.
https://anchore.com/blog/comparing-vulnerabilities-across-image-versions-anchore-enterprise-api
0
0
0
0
Open post
CMMC Phase 2 audits are coming. "We think we're compliant" won't fly with a C3PAO auditor, you need an exportable paper trail.
How Anchore Enterprise generates that evidence automatically: https://anchore.com/blog/how-to-automate-cmmc-compliance-for-containers-sboms/
0
0
0
0
Open post
🚨 The EU just made SBOMs mandatory for all software products!
Our guide breaks down the Cyber Resilience Act requirements and provides a roadmap to compliance before the 2027 deadline.
Don't wait—start building your SBOM strategy today.
🔗 https://anchore.com/sbom/eu-cra/
#SBOM #CRA
0
0
0
0
Open post
A zero-day vulnerability is inevitable. The question is whether your organization is ready. Our latest on-demand webinar highlights the contrast between manual searches and an SBOM-powered response. Stop the chaos and start executing a plan.
➡️ Ready to see the difference? Watch the on-demand webinar: https://go.anchore.com/rapid-incident-response-with-sboms/ #SBOM #IncidentResponse #Cybersecurity
0
0
0
0
Open post
Operation Stormbreaker cut an 18-month ATO cycle to 15 minutes. USMC MCCS, Raven Solutions, and Anchore break down the DevSecOps architecture behind it. July 29, 9am PT. Register: https://go.anchore.com/architecting-a-DoD-software-factory.html
0
0
0
0
Open post
"If an image passes a scan Tuesday, is it still compliant Friday?" Chadd Owen, Anchore Solution Architect, on why container drift is a bigger CMMC risk than most contractors realize: https://anchore.com/blog/how-to-automate-cmmc-compliance-for-containers-sboms/
0
0
0
0
Open post
What is CompOps? It's Compliance Operations, and it replaces painful manual audits with continuous, automated governance.
✅ Automate continuous evidence
✅ Give devs real-time feedback
✅ Reclaim engineering hours
Learn more in our latest whitepaper: https://go.anchore.com/Modern-Blueprint-for-Continuous-Compliance.html#DevSecOps
0
0
0
0
Open post
CMMC 2.0 Phase 2 starts Nov 10, 2026. Level 2 contractors face mandatory C3PAO audits. FedRAMP cloud alone won't cover you, container images and SBOMs still need proof. How we automate NIST 800-171 mapping: https://anchore.com/blog/how-to-automate-cmmc-compliance-for-containers-sboms/
0
0
0
0
Open post
Two versions of the same container image can look nearly identical. The vulnerability profile underneath usually isn't. Ben Lang shows how to compare versions directly using the Anchore Enterprise API.
https://anchore.com/blog/comparing-vulnerabilities-across-image-versions-anchore-enterprise-api
0
0
0
0
Open post
CMMC 2.0 Phase 2 starts Nov 10, 2026. Level 2 contractors face mandatory C3PAO audits. FedRAMP cloud alone won't cover you, container images and SBOMs still need proof. How we automate NIST 800-171 mapping: https://anchore.com/blog/how-to-automate-cmmc-compliance-for-containers-sboms/
0
0
0
0
Open post
MCP is having a moment. @josh.bressers.name wanted to know: what are we actually shipping?
9,000 vulns
263 critical findings
36K+ NPM packages
Outdated base images
Not fear-mongering—just data-driven reality. Read his analysis: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
#MCP #ContainerSecurity
0
0
0
0
Open post
Tomorrow: Anchore + Chainguard demo STIG checks running on shell-less container images, live, no shell execution required.
10am PT / 1pm ET.
Sign up: https://go.anchore.com/running-STIG-with-Chainguard#STIG #Chainguard
0
0
0
0
Open post
SBOMs aren't just a compliance checkbox. Used continuously, they show how vulns inherit across shared image layers.
But SBOMs alone can't answer: is this actually exploitable? See why VEX fills that gap: https://anchore.com/blog/operationalizing-vex-in-container-security-pipelines
0
0
0
0
Open post
You can create accounts, provision users, grant RBAC roles, wire up a registry, and update system config atomically, all from one script against the Anchore Enterprise API. No UI required: https://anchore.com/blog/automating-admin-tasks-via-anchore-enterprise-api/
0
0
0
0
Open post
Finding out a specific package is vulnerable is only step one. You then have to map that to specific running pods in your frontend service. Our new blog discusses using a Kubernetes inventory agent to collapse this impact analysis down to minutes.
https://anchore.com/blog/compliance-operations-making-kubernetes-audit-ready-by-design/
0
0
0
0
Open post
⚠️ Root user running
⚠️ Secrets in plain text
⚠️ Missing SBOM
Each one maps to a specific NIST 800-171 control your CMMC audit will check. The Anchore Enterprise CMMC Policy Pack automates all of it. https://anchore.com/blog/how-to-automate-cmmc-compliance-for-containers-sboms/
0
0
0
0
Open post
Treating compliance as version-controlled code is necessary when dealing with the EU Cyber Resilience Act. The manual reconstruction of deployment histories is inefficient and error-prone. Read our analysis on making Kubernetes continuously audit-ready by design. https://anchore.com/blog/compliance-operations-making-kubernetes-audit-ready-by-design/
0
0
0
0
Open post
Tomorrow, 9am PT: how Operation Stormbreaker cut an 18-month ATO cycle to 15 minutes.
USMC MCCS, Raven Solutions, and Anchore break down the platform behind it.
Register: https://go.anchore.com/architecting-a-DoD-software-factory.html
0
0
0
0
Open post
Control your supply chain risk. SBOM usage for vulnerability management jumped to 40%. It is a necessity for EU CRA compliance. Automate SBOM-powered analysis to reduce manual burden, stay compliant by default, and ship secure software faster. https://anchore.com/blog/eu-cra-vulnerability-management/
0
0
0
0
Open post
Tired of noisy vulnerability scanners? 🎯
Our own Chadd Owen explains how eliminating heuristic assumptions drastically improves scan accuracy: "We look at what's on disk, what's in the file system. The result is extremely accurate data."
Read more: https://anchore.com/blog/mattermost-container-vulnerability-scanning/#SBOM #VulnerabilityManagement
0
0
0
0
Open post
FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
0
0
0
0
Open post
Built on 30M+ download open source tools (Syft & Grype) 🔧
Community-proven, enterprise-hardened 💪
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
0
0
0
0
Open post
FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
0
0
0
0
Open post
Post 7 of 7: automating admin tasks in the Anchore Enterprise API. Accounts, users, RBAC roles, and registry configs, all scriptable instead of clicked through in the UI. Read Ben Lang's final post in the series: https://anchore.com/blog/automating-admin-tasks-via-anchore-enterprise-api/
0
0
0
0




