Sign in

Anchore

@anchore.com
190 followers 1K following 1.1K posts

Securing and managing the software supply chain. Proud parent of @syftproject.bsky.social and @grypeproject.bsky.social

PostsRepliesMedia
Anchore @anchore.com · 48m
Shift-left compliance checking ⬅️ Catch violations before deployment, not during audits 🛡️ anchore.com/platform/enforce #SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
000
Anchore @anchore.com · 16h
A new KEV entry lands. Which of your releases ship the affected package? With a 24-hour CRA early warning window, stored SBOMs make that a search across every release. See the workflow: anchore.com/blog/what-eu-cra-24-hou…
000
Anchore @anchore.com · 20h
@josh.bressers.name cuts through the complexity: "Your infrastructure could be a container image... how do you even start to understand what's inside?" Stop guessing. Start using SBOMs. 💡 anchore.com/blog/sbom-is-an-investm…
000
Anchore @anchore.com · 23h
78% of security teams have visibility into less than half their vendor ecosystem. Manual, spreadsheet-driven compliance can't keep pace. Our on-demand webinar covers what continuous compliance actually requires. Watch now: go.anchore.com/the-security-tax-wit…
000
Anchore @anchore.com · 02/10/2026
Under FedRAMP 20x Class C, you need to show each image met the requirement when it shipped and has been monitored daily since. The last scan before your 3PAO visit doesn't cover that. How we automate the evidence: anchore.com/blog/enforce-fedramp20x…
000
Anchore @anchore.com · 01/10/2026
September 2026 brings mandatory exploit reporting under the new EU CRA. If you are scrambling to figure out exactly what pods are running right now, you need a different approach. Read our white paper: anchore.com/blog/compliance-operati…
000
Anchore @anchore.com · 01/10/2026
With the EU's Cyber Resilience Act, #SoftwareTransparency isn't optional. It's a global mandate. We're thrilled to announce #SBOM pioneer @allanfriedman.bsky.social is joining the Anchore board to help nav... anchore.com/blog/anchore-welcomes-s…
000
Anchore @anchore.com · 01/10/2026
#SBOMs are becoming a standard requirement for secure software development. Learn how to generate, manage, and use SBOMs effectively to improve security posture, automate compliance, and reduce risk ac... get.anchore.com/sbom101-guide-for-d… #devsecops #compliance #security
001
Anchore @anchore.com · 01/10/2026
An assessor wants your inventory matched to a control number, on demand. Our blog covers mapping SBOMs to NIST 800-53 CM-8 and CISA KEV vulnerabilities to SI-2 in Anchore Enterprise. anchore.com/blog/fedramp-cmmc-in-20…
000
Anchore @anchore.com · 29/09/2026
The EU CRA's 24-hour reporting requirement took effect September 11, 2026, and covers products already on the EU market. New on our blog: what your SBOM and policy pipeline need ready. anchore.com/blog/what-eu-cra-24-hou…
000
Anchore @anchore.com · 28/09/2026
In July 2026, an autonomous AI agent chained vulnerabilities in Hugging Face's data pipeline to steal credentials, no human at the keyboard. Our on-demand webinar shows where attacks are headed next. Watch now: go.anchore.com/the-security-tax-wit…
000
Anchore @anchore.com · 27/09/2026
Anchore SBOM Score = CVSS + EPSS + KEV status 📊 Because not all vulnerabilities are created equal ⚠️ anchore.com/platform/sbom #SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
000
Anchore @anchore.com · 26/09/2026
Zero-day incidents like Log4Shell highlight the need for a better way to respond. This on-demand webinar explains how an SBOM-powered approach helps go from discovering a new vuln to creating a remediation list in minutes. go.anchore.com/rapid-incident-respo… #SBOM
000
Anchore @anchore.com · 26/09/2026
CMMC Phase 2 is paused. Phase 1 self-assessment and DFARS 252.204-7012 are not. Our latest blog covers why continuous evidence beats waiting to see what CMMC becomes. anchore.com/blog/fedramp-cmmc-in-20…
000
Anchore @anchore.com · 24/09/2026
Live in 1 hour. STIG checks, shell-less Chainguard images, no shell required. Final call to sign up: go.anchore.com/running-STIG-with-Chainguard
000
Anchore @anchore.com · 24/09/2026
Enter a CVE ID or package name, and instantly get every affected image across your fleet. No new scan, just a simple query. We wrote a deeper walkthrough on scripting the full blast-radius calculation using ... anchore.com/blog/what-your-vulnerab…
000
Anchore @anchore.com · 23/09/2026
Tomorrow: live STIG checks on shell-less Chainguard images. Anchore + Chainguard, 10am PT. go.anchore.com/running-STIG-with-Chainguard
000
Anchore @anchore.com · 22/09/2026
FedRAMP renamed itself (Authorization → Certification, Classes A-D). CMMC Phase 2 got paused. Both within 2 weeks of each other. On our blog: what actually changed, and what didn't, for your ATO. anchore.com/blog/fedramp-cmmc-in-20…
000
Anchore @anchore.com · 21/09/2026
Live demo: pulling a shell-less Chainguard image, running it through Anchore's policy engine, straight to the STIG audit trail your ATO reviewer will want. Sept 24, 10am PT / 1pm ET. go.anchore.com/running-STIG-with-Chainguard
000
Anchore @anchore.com · 21/09/2026
New in Anchore Enterprise v6.2: an MCP Server for AI agents. Direct access to SBOMs, vuln findings, and policy results, no duct-taped API scripts needed. anchore.com/blog/extending-supply-c…
000
Anchore @anchore.com · 20/09/2026
SBOM-first isn't just a buzzword—it's the architecture that makes continuous security actually possible 🔄 Feel the difference ⚡ anchore.com/platform #SBOM #CRA #SoftwareSupplyChain #Compliance
000
Anchore @anchore.com · 19/09/2026
Stop guessing what "GPL-ish" means. Grant groups licenses by risk so you can approve/deny in seconds. One list, not fifty rules. 👉 anchore.com/blog/grants-release-0-3… #OpenSource #SupplyChainSecurity #Compliance #DevSecOps
110
Anchore @anchore.com · 18/09/2026
New in Anchore Enterprise v6.2: native AI model detection. GGUF files and Docker Models now get indexed as packages in your SBOM catalog, right alongside your open source dependencies. anchore.com/blog/extending-supply-c…
010
Anchore @anchore.com · 18/09/2026
No CVE yet, just a known-bad package? Our blog walks through the use of Anchore Enterprise's API to query by package version instead of waiting for an ID to exist. anchore.com/blog/what-your-vulnerab…
000
Anchore @anchore.com · 17/09/2026
Soften the image, or run two STIG workflows. That's the current tradeoff for shell-less images. Anchore Enterprise runs STIG checks on Chainguard images either way. Live Sept 24, 10am PT. go.anchore.com/running-STIG-with-Chainguard
000
Anchore @anchore.com · 15/09/2026
Anchore Enterprise v6.2 is out today. New: native AI model detection in your SBOM catalog, an MCP Server for AI agents, VEX-aware policy, and severity filtering. anchore.com/blog/extending-supply-c…
000
Anchore @anchore.com · 15/09/2026
A SharePoint RCE got patched July 14th. It was already being exploited as a zero-day. CISA added it to KEV 2 days later. Our latest blog covers what that means for your response process. anchore.com/blog/what-your-vulnerab…
000
Anchore @anchore.com · 14/09/2026
BOD 26-04 dropped CVSS-only prioritization: worst case, a 3-day remediation clock. FedRAMP moved its deadline up to Dec 7, 2026. anchore.com/blog/silence-is-now-a-s…
000
Anchore @anchore.com · 14/09/2026
For security engineering leaders: A detailed guide to the FedRAMP authorization process. Learn about the framework, roles, & a structured approach to achieving compliance. Essential for SaaS/PaaS/IaaS providers targeting the public sector. get.anchore.com/unlocking-the-feder…
000
Anchore @anchore.com · 13/09/2026
Shift-left compliance checking ⬅️ Catch violations before deployment, not during audits 🛡️ anchore.com/platform/enforce #SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
000
Anchore @anchore.com · 13/09/2026
MCP is having a moment. @josh.bressers.name wanted to know: what are we actually shipping? 9,000 vulns 263 critical findings 36K+ NPM packages Outdated base images Not fear-mongering—just data-driven real... anchore.com/blog/analyzing-the-top-… #MCP #ContainerSecurity
100
Anchore @anchore.com · 12/09/2026
HUGE NEWS! 📣 The "father of SBOM," @allanfriedman.bsky.social, is joining Anchore as a Board Advisor! We sat down with him to discuss the future of #SoftwareSupplyChainSecurity and what comes after SBOM.... anchore.com/blog/anchore-welcomes-s…
000
Anchore @anchore.com · 12/09/2026
Manually correlating CVE data across dynamic clusters is a headache for engineering teams. We need to stop treating audits as an annual ritual. Learn how continuous cluster polling keeps your records digest-ac... anchore.com/blog/compliance-operati…
000
Anchore @anchore.com · 12/09/2026
CRA demands SBOMs stored for 10 years. PCI-DSS 4 requires scans every 3 months minimum. Compliance isn't annual anymore—it's continuous. @josh.bressers.name explains why your DevOps team already knows how to solve this problem: anchore.com/blog/compliance-isnt-an…
000
Anchore @anchore.com · 11/09/2026
7 of 10 new CISA SBOM elements describe the document, not the software: Author, Signature, Tool Version, Generation Context. anchore.com/blog/silence-is-now-a-s…
000
Anchore @anchore.com · 11/09/2026
STIG scanners need a shell to run. Chainguard images don't ship one. That's a real problem for teams pursuing an ATO or FedRAMP. Live demo of the fix, Sept 24 - go.anchore.com/running-STIG-with-Chainguard
000
Anchore @anchore.com · 11/09/2026
Mean time to exploit a vulnerability is now an estimated -7 days (Google Cloud's Mandiant). 42% of vulnerabilities are exploited before public disclosure (CrowdStrike). New blog: why reactive scanning isn't ... anchore.com/blog/what-your-vulnerab…
000
Anchore @anchore.com · 10/09/2026
Starting in an hour. EU CRA's 24hr reporting deadline is tomorrow. Join now. go.anchore.com/bitsea-anchore-eu-cr…
000
Anchore @anchore.com · 09/09/2026
New from Anchore: an MCP server for Enterprise. Curated tools for triage and policy checks, a fallback for everything else, available now as a minimal footprint container. anchore.com/blog/anchore-ai-just-go…
000
Anchore @anchore.com · 09/09/2026
CRA Article 14 covers your full lifecycle, including third-party and OSS components. Tomorrow's session shows you how to govern it. go.anchore.com/bitsea-anchore-eu-cr… #CRA
000
Anchore @anchore.com · 08/09/2026
CISA's new SBOM rules (23 elements, up from 14) kill the 1-level dependency depth rule. Coverage requires transitive deps: absence is now a claim, not "we didn't look." anchore.com/blog/silence-is-now-a-s…
000
Anchore @anchore.com · 07/09/2026
Vague data in, vague decisions out. Our new MCP server hands agents the same deterministic vuln, policy, and SBOM data our security team already relies on. anchore.com/blog/anchore-ai-just-go…
000
Anchore @anchore.com · 07/09/2026
ENISA's CRA reporting format and 24hr window, walked through live on Sept 10. go.anchore.com/bitsea-anchore-eu-cr… #ENISA
000
Anchore @anchore.com · 07/09/2026
An auditor rarely asks for your process. They ask what was running last Tuesday. Anchore Enterprise generates a point-in-time inventory for any date in your retention window anchore.com/blog/your-kubernetes-cl…
000
Anchore @anchore.com · 06/09/2026
Supply chain attacks ↗️ 742% in 2023 Your traditional security stack wasn't built for this fight. SBOM-first architecture changes everything ⚡ anchore.com/platform #SoftwareSupplyChain #SBOM #CyberSecurity
000
Anchore @anchore.com · 05/09/2026
Enforce continuous compliance. Supply chain security focus has increased 200%. The EU CRA requires lifecycle accountability. Shift left and centralize component visibility to eliminate bottlenecks, stay compliant by default, and ship secur... anchore.com/blog/eu-cra-vulnerabili…
000
Anchore @anchore.com · 04/09/2026
Patched image in the registry doesn't mean the pod running it got redeployed. We wrote about anchore-k8s-inventory: polls the Kubernetes API directly, tracks images by digest instead of tag anchore.com/blog/your-kubernetes-cl…
110
Anchore @anchore.com · 03/09/2026
Not every vulnerability starts EU CRA's 24-hour reporting clock, only actively exploited ones do. We cover the actual definitions Sept 10. go.anchore.com/bitsea-anchore-eu-cr… #CRA
000
Anchore @anchore.com · 03/09/2026
We shipped an MCP server for Anchore Enterprise. Agents get native access to vuln findings, policy results, and SBOM data, no custom glue code. Available now as a container image. anchore.com/blog/anchore-ai-just-go…
000
Anchore @anchore.com · 03/09/2026
EO 14306 removed CISA's central role in validating SSDF attestations. Vendors now hold their own audit-ready proof. What that means for your next federal RFP: anchore.com/blog/one-sbom-five-audi…
000