A lot has happened over the last few months for Anchore Open-Source – as a small OSS engineering team, we’re proud of the work we’ve done in the creation and ongoing evolution of the Anchore OSS tools, but are equally honored and thankful to work in concert with our vibrant community of users and contributors of all kinds.
This week, the primary Anchore OSS projects (Syft, Grype and Grant) have tipped past the 50 Million Downloads mark, which we feel is a milestone well worth sharing and celebrating with all of you – after all, you’re the ones who, through your discussions, bug reports, feature requests, code contributions, community meetings and use of the tool suite have made this milestone happen – thank you, and congratulations!!
Quick tour of recent activity
Anchore OSS projects continue to grow across the board – here are some fun rollups derived from public github project stats, as of January 2026:
| Project | Stars | Contributors | Community Reach |
| Syft | 8.3k+ +6.4% | 217 +4.8% | Powering SBOM generation for 450+ dependent projects with many enterprises amongst them. |
| Grype | 11.4k+ +5.6% | 134 +3.1% | Proving the principle of ‘get the data (SBOM), use the data (vuln scan)’: used by 160+ major public repos. |
| Grant | 133 +18.7% | 12 +9.1% | A specialized, burgeoning tool for license policy and compliance. |
Here is a look back at just a few of the recent technical themes where a lot of improvements and new functionality has been delivered over just the past couple of months:
- Syft/Grype/Vunnel – extended the breadth of software coverage for SBOM generation vulnerability scanning, and license detection through the addition of new software ecosystems, hardened container image projects, new binary catalogers, and new Linux distributions
- Grant – can now ingest even richer license data from the SBOM layer for more accurate license compliance and policy checking capabilities
- Syft – added support for cataloging an entirely new type of material – LLM models in GGUF format, to surface AI/ML elements in the form of an (S/AI)BOM
Thank you again all around – working together with all of you to hit 50 million downloads in just a few short years has been an incredible journey, and there is a lot more we have planned! At a time where the sheer pace of software being produced, and thus the surface area of the global software is exploding in magnitude, having the tech that gives you the ability to take a deep look at what your projects depend on – contextualize, check, validate, analyze – will continue to move from ‘best practice superpower’ to a ‘fundamental need’ in concert.
We love contributions – start topical discussions, report issues / bugs, contribute new features and bug fixes – come join us over on our newly launched docs site where you’ll find up-to-date links to the all of Anchore’s OSS project github pages, our community discourse, and guides for using and contributing to Anchore OSS!