Skip to content
@anchore

Anchore, Inc.

 Mastodon  Twitter   LinkedIn   Anchore Community Discourse 

Welcome 👋

We are Anchore. Securing and managing the software supply chain. Proud parents of Syft and Grype

Blog

We regularly write about what we're working on; here are some recent blog posts:

Community

We discuss our open source tools on Discourse. Here are some recent topics:

Pinned Loading

  1. syft syft Public

    CLI tool and library for generating a Software Bill of Materials from container images and filesystems

    Go 8.4k 763

  2. grype grype Public

    A vulnerability scanner for container images and filesystems

    Go 11.5k 739

  3. scan-action scan-action Public

    Anchore container analysis and scan provided as a GitHub Action

    JavaScript 267 87

  4. sbom-action sbom-action Public

    GitHub Action for creating software bill of materials using Syft.

    TypeScript 219 34

  5. kubernetes-admission-controller kubernetes-admission-controller Public

    Service implementation for a Kubernetes Dynamic Webhook controller for interacting with Anchore

    Go 65 28

  6. anchore-charts anchore-charts Public

    Helm charts for Anchore tools and services

    Python 53 73

Repositories

Showing 10 of 100 repositories
  • grype Public

    A vulnerability scanner for container images and filesystems

    anchore/grype’s past year of commit activity
    Go 11,513 Apache-2.0 739 329 26 Updated Feb 9, 2026
  • anchore/nvd-data-overrides’s past year of commit activity
    Python 49 CC0-1.0 6 1 0 Updated Feb 9, 2026
  • vulnerability-index-spec-files Public

    Controls the rendering of specific vulnerability data records

    anchore/vulnerability-index-spec-files’s past year of commit activity
    0 CC0-1.0 0 0 0 Updated Feb 9, 2026
  • anchore/vulnerability-data-tools’s past year of commit activity
    Python 16 Apache-2.0 4 3 1 Updated Feb 9, 2026
  • anchore/cve-data-enrichment’s past year of commit activity
    Shell 17 CC0-1.0 9 1 0 Updated Feb 9, 2026
  • vulnerability-match-labels Public

    Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners

    anchore/vulnerability-match-labels’s past year of commit activity
    Python 14 CC0-1.0 10 4 1 Updated Feb 9, 2026
  • security-identifiers Public

    Contains the Anchore-allocated security identifiers and the relationships to upstream security data source identifiers

    anchore/security-identifiers’s past year of commit activity
    1 CC0-1.0 0 0 0 Updated Feb 9, 2026
  • binny Public

    Manage a directory of binaries without a package manager

    anchore/binny’s past year of commit activity
    Go 48 Apache-2.0 4 8 4 Updated Feb 9, 2026
  • yardstick Public

    Compare vulnerability scanners results (to make them better!)

    anchore/yardstick’s past year of commit activity
    Python 27 Apache-2.0 7 6 2 Updated Feb 9, 2026
  • go-make Public
    anchore/go-make’s past year of commit activity
    Go 0 Apache-2.0 1 0 3 Updated Feb 9, 2026