Anchore Blog

Introducing Anchore Federal

Open source software can produce surprising results. Once you create a project or application that solves real problems – and make it available under a license that enables it to be distributed throughout the world – it won’t be long before it turns up in all sorts of interesting projects and organizations. This has certainly …

Introducing Anchore Federal Read More »

Anchore: 2020 and Beyond

Today marks a major milestone in the Anchore journey. Just a little over 3 years since we opened our doors, we have secured a substantial $20M round of funding that will allow us to address the next wave of container users around the world. I am utterly pleased and totally blown away by what a …

Anchore: 2020 and Beyond Read More »

A Buyers’ Guide to DevSecOps

Echoing Dickens, for many in software security, it is the best of times and it is the worst of times. Every day brings literal front page news about software compromises resulting in massive data leaks. Meanwhile, the use of cloud-native technologies has meant that the variety and complexity of software being deployed has outstripped the …

A Buyers’ Guide to DevSecOps Read More »

Announcing Anchore Enterprise 2.2

Just in time for the holidays, Anchore Enterprise 2.2, our latest update, is now generally available to all of our customers. For this release, we focus on third-party integrations to send notifications, and a new system dashboard to help customers view the status of their systems. This new enterprise release is based on open source …

Announcing Anchore Enterprise 2.2 Read More »

Anchore for GitHub Actions

Today at Github Universe, we are announcing the availability of the Anchore Container Scan action for GitHub. Actions allow developers to automate CI/CD workflows, easily integrating tools like Anchore into their build processes. This new action was designed for teams looking to introduce security into their development processes. You can find the action in the …

Anchore for GitHub Actions Read More »

The DeliveryHero Story: Inviting Security to the Party

Last week, the team at DeliveryHero posted the first in a series of articles about bolstering container security and compliance in their DevOps container orchestration model using Anchore Engine. We think they did a fantastic job explaining their goals and sharing the progress they have made. Their article is a great read for those who …

The DeliveryHero Story: Inviting Security to the Party Read More »

Benefits of Static Image Inspection and Policy Enforcement

In this post, I will dive deeper into the key benefits of a comprehensive container image inspection and policy as code framework A couple of key terms: Comprehensive Container Image Inspection: Complete analysis of a container image to identify it’s entire contents: OS & non-OS packages, libraries, licenses, binaries, credentials, secrets, and metadata. Importantly: storing …

Benefits of Static Image Inspection and Policy Enforcement Read More »

Success With Anchore | Best Practices from our Customers

Introduction Successful container and CI/CD security encompasses not only vulnerability analysis but also a mindset based on integrating security with every step of the Software Development Life Cycle (SDLC). At Anchore, we believe incorporating early and frequent scanning with policy enforcement can help reduce overall security risk. This blog shares some of the elements that …

Success With Anchore | Best Practices from our Customers Read More »

Anchore Talk | Redefining the Software Supply Chain

We are pleased to announce Anchore Talks, a series of short webinars to help improve Kubernetes and Docker security best practices. We believe it is important to have excellent security measures in place when adopting containers, and that drives every decision we make when developing Anchore Enterprise and Anchore Engine. These talks, no longer than …

Anchore Talk | Redefining the Software Supply Chain Read More »