Shift-left compliance checking ⬅️
Catch violations before deployment, not during audits 🛡️
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
One small change can make a big difference in software supply chain security.
PyPI has introduced a new safeguard that rejects uploads of new files to package releases older than 14 days. This helps prevent attackers who compromise a maintainer’s account or publishing pipeline from silently adding malicious files to a long-trusted package version months after it was released.
While this doesn’t eliminate all supply chain threats, it significantly reduces the risk of “package poisoning” attacks against pinned dependencies and encourages immutable releases, a security best practice every ecosystem should strive for.
Security isn’t about a single silver bullet, it’s about layering defenses that make attacks increasingly difficult.
Could we see similar protections become the standard across other package registries like npm, NuGet, and RubyGems?
https://cybersecuritynews.com/pypi-14-day-release-lock/amp/
#CyberSecurity #AppSec #SupplyChainSecurity #PyPI #Python #DevSecOps #SoftwareSecurity #OpenSource #SecureByDesign #SoftwareSupplyChain #Infosec
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
Built on 30M+ download open source tools (Syft & Grype) 🔧
Community-proven, enterprise-hardened 💪
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
"Bring Your Own SBOM" sounds simple...
Until you try to manage thousands of them 📊
Scale is everything 📈
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Supply chain attacks ↗️ 742% in 2023
Your traditional security stack wasn't built for this fight.
SBOM-first architecture changes everything ⚡
https://anchore.com/platform/
#SoftwareSupplyChain #SBOM #CyberSecurity
Anchore SBOM Score = CVSS + EPSS + KEV status 📊
Because not all vulnerabilities are created equal ⚠️
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
SBOM-first isn't just a buzzword—it's the architecture that makes continuous security actually possible 🔄
Feel the difference ⚡
https://anchore.com/platform/
#SBOM #CRA #SoftwareSupplyChain #Compliance
FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
I wonder if there's a software business model where you buy the software for the binary and the source code? The source code is not exactly open, but is available on that specific version. I'm also wondering how that would work for the software supply chain. 🤔
#Software #business #foss #oss #intelectualProperty #sourcecode #development #developers #SoftwareSupplyChain
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Scale-out architecture for web-scale environments 📈
Because your containers don't wait for security scans ⏱️
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Your MCP server might be the weakest link—here's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
#MCP #SoftwareSupplyChain #ContainerSecurity #DevSecOps
SBOM-first isn't just a buzzword—it's the architecture that makes continuous security actually possible 🔄
Feel the difference ⚡
https://anchore.com/platform/
#SBOM #CRA #SoftwareSupplyChain #Compliance
Scale-out architecture for web-scale environments 📈
Because your containers don't wait for security scans ⏱️
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
"Source code is to build artifacts as data sets are to AI models."
Kate Stewart (The Linux Foundation) explains why you can't trust your AI if you don't know what trained it.
Read why the "S" in SBOM is standing for System: https://anchore.com/blog/the-s-in-sbom-is-for-system/
#SoftwareSupplyChain #SBOM