Platform | SBOM

Anchore SBOM

Manage internal and external SBOMs in a single location to track software supply chain issues and meet compliance requirements as a software supplier.

Achieve Software Supply Chain Transparency

Up to 90% of any given software application today is made up of open source components. Anchore SBOM brings comprehensive visibility into the software components present in both internally developed and third-party supplied software. Upload SBOMs in industry standard formats and categorize your products and services so you can identify and mitigate security and compliance risks. Use Anchore SBOM to build trust inside and outside of your organization and comply with the compliance requirements in the US and Europe.

Ingest, Manage & Analyze

Bring your own SBOM (BYOS)

Upload your own internally generated SBOMs or those given to you by your suppliers in one of the formal standards and avoid SBOM sprawl by creating a single, canonical location for managing SBOM documents. Use metadata to help describe and track the SBOM and apply version control to manage lifecycles.

Validation of SBOM content

Prevent junk SBOMs clogging up the system by using Anchore’s SBOM’s validation checks to assess format and schema compliance. Ensure fields are filled in correctly to meet the National Telecommunications and Information Administration (NTIA) minimum requirements to meet compliance demands from regulators and assessors.

Group Management

Collect SBOMs into groups to represent teams, projects, products, or services. Each group can be version controlled to represent “living” deployments or immutable deployments that have been shipped. Download the group contents as SBOM documents for delivery to downstream consumers.

Vulnerability Scanning and Prioritization with Anchore Score

Analyze every SBOM for vulnerabilities and receive an Anchore Score to prioritize remediation efforts. The Anchore Score looks at a range of variables including CVSS, EPSS, and KEV data to help you understand the risk and focus on the right vulnerabilities to fix first.


FAQs

Anchore SBOM supports uploading SBOMs in the following versions:

    CycloneDX

    • JSON: Versions 1.2 – 1.6
    • XML: Versions 1.0 – 1.6
    SPDX

    • JSON: Versions 2.2 – 2.3
    • Tag-Value: Versions 2.1 – 2.3
      Syft SBOMs are exported in the following formats:

      • SPDX v2.3
      • CycloneDX v1.6

Anchore Enterprise generates SBOMs for containers as part of CI/CD, registry, or runtime scanning. This allows it to generate additional data about Dockerfile content, image content, and other metadata. This extra information can be used for additional scans for malware or secrets, or compliance checks as part of the Anchore Enforce module. SBOMs uploaded to the system for non-Anchore tools are scanned for vulnerability information only.

Anchore allows you to upload SBOMs generated by non-Anchore tools representing both codebases under your control (internal SBOMs) as well as third-party SBOMs provided to your organization by partners, contractors, and upstream suppliers. These SBOMs represent assets not available for Anchore scanning and allow unification of security information between artifacts scanned by Anchore and those represented by uploaded SBOMs.

Uploaded SBOMs are both stored for future use and analyzed for both quality and content, and provide the following information:

  • SBOM document information
  • An assessment of the overall SBOM quality
  • SBOM contents (packages)
  • Associated security vulnerabilities

The SBOM quality checks are based on the following criteria:

  • Valid and supported SBOM format
  • Valid and supported SBOM schema
  • Content check for required elements

SBOM groups allow for organizing multiple SBOMs into a logical set. An SBOM group may represent a business unit, product team, application, sub-module, or an arbitrary set of SBOMs. SBOM groups also allow a rollup of all overall quality and security vulnerabilities across the constituent SBOMs.

The Anchore Score is a computed composite security index that provides a numeric value for each vulnerability in the system. It is derived from a combination of the CVSS score, vulnerability severity, EPSS percentile, and KEV status, but can also factor in additional data. Currently, the CVSS score & vulnerability severity, EPSS percentile, and KEV status are equally weighted. The Anchore Score is used to generate the Anchore Rank value indicating the relative importance of a given vulnerability within a particular set of vulnerabilities defined by an SBOM Group or individual SBOM context. This ordering helps users focus on the most critical issues for efficient security analysis and remediation planning.

Anchore SBOM is included in all Anchore Enterprise subscriptions.

Explore our solutions

Federal Compliance

Automate compliance checks using out-of-the-box and custom policies.

Open Source Security

Improve open source security by easily tracking direct and transitive open source dependencies to identify and fix vulnerabilities early.

DevSecOps

Automate DevSecOps for your cloud-native software supply chain with an API-first DevSecOps solution.

Container Security Solution

Identify and remediate container security risks and monitor post-deployment for new vulnerabilities.

FedRAMP Vulnerability Scanning

Meet the new FedRAMP Vulnerability Scanning Requirements for Containers and achieve compliance faster with Anchore.

Container Vulnerability Scanning

Reduce false positives and false negatives with best-in-class signal-to-noise ratio.

Kubernetes Images Scanning

Allow or prevent deployment of images based on flexible policies and continuously monitor the inventory of insecure images running in your clusters.

Container Registry Scanning

Identify and remediate new risks and vulnerabilities as they emerge.

CI/CD Security & Compliance

Embed security and compliance into your CI/CD pipeline to uncover vulnerabilities, secrets, and malware in your automated build processes.

SBOM Management

Get comprehensive visibility of your software components and ensure vulnerability accuracy with the most complete SBOM available. Generate, store, analyze, and monitor SBOMs across the application lifecycle to identify software dependencies and improve supply chain security.

Container Compliance

Automate compliance checks using out-of-the-box and custom policies.

Speak with our security experts

Learn how Anchore’s SBOM-powered platform can help secure your software supply chain.