Remote
Securing and managing the software supply chain. Proud parent of @syft@fosstodon.org and @grype@fosstodon.org
72
Followers
21
Following
50
Posts
Joined June 13, 2024
Anchore:
Blog:
Open Source:
Posts
Manual security creates a visibility crisis. You can't secure what you can't see. 📉
Step 1: Generate a baseline SBOM instantly to stop accumulating operational debt.
Watch the full on-demand webinar for automating and scaling the rest: https://go.anchore.com/automate-generate-manage-sboms/
Open post
Shift-left compliance checking ⬅️
Catch violations before deployment, not during audits 🛡️
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
0
0
0
0
Open post
EU CRA non-compliance: fines up to €15M or 2.5% of global turnover. Plus national authorities can ban your products from the EU market.
First deadline is September 11, 2026 — 24-hour exploit reporting.
Here's what you need to build before then. https://anchore.com/blog/the-eu-cra-reporting-deadline-heres-what-you-need/
0
0
0
0
Open post
VEX gives you the exploitability signal. Turning it into a consistent policy decision across pipelines is the hard part.
Guest author, Devashri Datta, proposes a structured interpretation layer to bridge the two: https://anchore.com/blog/operationalizing-vex-in-container-security-pipelines
0
0
0
0
Open post
We start in 1 hour.
Operation Stormbreaker's cATO architecture, live with USMC MCCS, Raven Solutions, and Anchore.
Join: https://go.anchore.com/architecting-a-DoD-software-factory.html
0
0
0
0
Open post
EU CRA's 24-hour vulnerability reporting requirement: September 11, 2026.
That's 45 days to have automated KEV enrichment, alerting, and notification templates in production.
We published a phased compliance checklist + a white paper on the full mandate. Both free. https://anchore.com/blog/the-eu-cra-reporting-deadline-heres-what-you-need/
0
0
0
0
Open post
Tomorrow, 9am PT: how Operation Stormbreaker cut an 18-month ATO cycle to 15 minutes.
USMC MCCS, Raven Solutions, and Anchore break down the platform behind it.
Register: https://go.anchore.com/architecting-a-DoD-software-factory.html
0
0
0
0
Open post
CMMC Phase 2 audits are coming. "We think we're compliant" won't fly with a C3PAO auditor, you need an exportable paper trail.
How Anchore Enterprise generates that evidence automatically: https://anchore.com/blog/how-to-automate-cmmc-compliance-for-containers-sboms/
0
0
0
0
Open post
The problem with legacy SCAP tools? They trust the file system too much.
We grabbed this clip from our session with MITRE because it perfectly explains the shift to "Active Testing."
It's not enough to verify sshd_config exists. You have to query the daemon to see what it's actually enforcing.
See how we handled this in RHEL 9 & K8s: https://go.anchore.com/webinar-stig-in-action-with-mitre/
1
0
0
0
Open post
STIG scanning tools historically struggle with distroless images because they require an in-container shell. That gap is closed. Anchore Enterprise now evaluates STIG controls on shell-less @chainguard_dev images directly at the image layer. https://anchore.com/blog/stig-compliance-chainguard-images-now-supported/
0
0
0
0
Open post
Mitigate vulnerability noise. EU CRA incident reporting starts in 2026. You can't report what you cannot see. Stop manual triage & deploy continuous monitoring to accelerate remediation. Enforce policy gates to stay compliant by default & ship secure software faster. https://anchore.com/blog/eu-cra-vulnerability-management/
0
0
0
0
Open post
@joshbressers: "If you can't search your past builds, you can't bound your blast radius. SBOMs turn a frantic morning into a simple query."
His zero-day incident response story from inside Anchore's response to the NPM supply chain attack:
https://anchore.com/blog/a-zero-day-incident-response-story-from-the-watchers-on-the-wall/
0
0
0
0
Open post
Finding out a specific package is vulnerable is only step one. You then have to map that to specific running pods in your frontend service. Our new blog discusses using a Kubernetes inventory agent to collapse this impact analysis down to minutes.
https://anchore.com/blog/compliance-operations-making-kubernetes-audit-ready-by-design/
0
0
0
0
Open post
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
0
0
0
0
Open post
FedRAMP compliance in weeks, not months ⚡
Ready-to-deploy policy packs for instant compliance feedback 📋
https://anchore.com/platform/enforce/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance
0
0
0
0
Open post
Teams that crack cATO ship mission software in minutes, not months. That's the edge Operation Stormbreaker built.
See how, July 29 with USMC MCCS, Raven Solutions, and Anchore.
https://go.anchore.com/architecting-a-DoD-software-factory.html
0
0
0
0
Open post
SBOMs aren't just a compliance checkbox. Used continuously, they show how vulns inherit across shared image layers.
But SBOMs alone can't answer: is this actually exploitable? See why VEX fills that gap: https://anchore.com/blog/operationalizing-vex-in-container-security-pipelines
0
0
0
0
Open post
A critical CVE in code that never runs trips the same alert as one in an exposed path. Severity scores can't tell the difference. VEX can.
New post by a guest author on operationalizing VEX in container pipelines: https://anchore.com/blog/operationalizing-vex-in-container-security-pipelines
0
0
0
0
Open post
You can create accounts, provision users, grant RBAC roles, wire up a registry, and update system config atomically, all from one script against the Anchore Enterprise API. No UI required: https://anchore.com/blog/automating-admin-tasks-via-anchore-enterprise-api/
0
0
0
0
Open post
MCP is having a moment. @josh.bressers.name wanted to know: what are we actually shipping?
9,000 vulns
263 critical findings
36K+ NPM packages
Outdated base images
Not fear-mongering—just data-driven reality. Read his analysis: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
#MCP #ContainerSecurity
0
0
0
0
Open post
Control your supply chain risk. SBOM usage for vulnerability management jumped to 40%. It is a necessity for EU CRA compliance. Automate SBOM-powered analysis to reduce manual burden, stay compliant by default, and ship secure software faster. https://anchore.com/blog/eu-cra-vulnerability-management/
0
0
0
0
Open post
What is CompOps? It's Compliance Operations, and it replaces painful manual audits with continuous, automated governance.
✅ Automate continuous evidence
✅ Give devs real-time feedback
✅ Reclaim engineering hours
Learn more in our latest whitepaper: https://go.anchore.com/Modern-Blueprint-for-Continuous-Compliance.html
#DevSecOps
0
0
0
0
Open post
Built on 30M+ download open source tools (Syft & Grype) 🔧
Community-proven, enterprise-hardened 💪
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
0
0
0
0
Open post
"Bring Your Own SBOM" sounds simple...
Until you try to manage thousands of them 📊
Scale is everything 📈
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
0
0
0
0
Open post
"If an image passes a scan Tuesday, is it still compliant Friday?" Chadd Owen, Anchore Solution Architect, on why container drift is a bigger CMMC risk than most contractors realize: https://anchore.com/blog/how-to-automate-cmmc-compliance-for-containers-sboms/
0
0
0
0
Open post
SPDX or CycloneDX — pick one. Using both creates friction, not coverage. That's one of 6 phases in our EU CRA Software Supply Chain Compliance Checklist. Download now → https://anchore.com/white-papers/eu-cra-software-supply-chain-checklist/
0
0
0
0
Open post
Onboarding a new team into Anchore Enterprise usually means clicking through account creation, user setup, and RBAC grants by hand. All of it is available via the API instead. Here's the script that does it end to end: https://anchore.com/blog/automating-admin-tasks-via-anchore-enterprise-api/
0
0
0
0
Open post
A zero-day vulnerability is inevitable. The question is whether your organization is ready. Our latest on-demand webinar highlights the contrast between manual searches and an SBOM-powered response. Stop the chaos and start executing a plan.
➡️ Ready to see the difference? Watch the on-demand webinar: https://go.anchore.com/rapid-incident-response-with-sboms/ #SBOM #IncidentResponse #Cybersecurity
0
0
0
0
Open post
Operation Stormbreaker cut an 18-month ATO cycle to 15 minutes. USMC MCCS, Raven Solutions, and Anchore break down the DevSecOps architecture behind it. July 29, 9am PT. Register: https://go.anchore.com/architecting-a-DoD-software-factory.html
0
0
0
0
Open post
Post 7 of 7: automating admin tasks in the Anchore Enterprise API. Accounts, users, RBAC roles, and registry configs, all scriptable instead of clicked through in the UI. Read Ben Lang's final post in the series: https://anchore.com/blog/automating-admin-tasks-via-anchore-enterprise-api/
0
0
0
0
Open post
⚠️ Root user running
⚠️ Secrets in plain text
⚠️ Missing SBOM
Each one maps to a specific NIST 800-171 control your CMMC audit will check. The Anchore Enterprise CMMC Policy Pack automates all of it. https://anchore.com/blog/how-to-automate-cmmc-compliance-for-containers-sboms/
0
0
0
0
Open post
🚨 The EU just made SBOMs mandatory for all software products!
Our guide breaks down the Cyber Resilience Act requirements and provides a roadmap to compliance before the 2027 deadline.
Don't wait—start building your SBOM strategy today.
🔗 https://anchore.com/sbom/eu-cra/
#SBOM #CRA
0
0
0
0
Open post
Tired of noisy vulnerability scanners? 🎯
Our own Chadd Owen explains how eliminating heuristic assumptions drastically improves scan accuracy: "We look at what's on disk, what's in the file system. The result is extremely accurate data."
Read more: https://anchore.com/blog/mattermost-container-vulnerability-scanning/
#SBOM #VulnerabilityManagement
0
0
0
0
Open post
Supply chain attacks ↗️ 742% in 2023
Your traditional security stack wasn't built for this fight.
SBOM-first architecture changes everything ⚡
https://anchore.com/platform/
#SoftwareSupplyChain #SBOM #CyberSecurity
0
0
0
0
Open post
"Fixed: 12. Introduced: 2. Persisting: 34, 8 with fixes available."
That's progress you can measure. Ben Lang shows how to get there with the Anchore Enterprise API.
https://anchore.com/blog/comparing-vulnerabilities-across-image-versions-anchore-enterprise-api
0
0
0
0
Open post
CMMC 2.0 Phase 2 starts Nov 10, 2026. Level 2 contractors face mandatory C3PAO audits. FedRAMP cloud alone won't cover you, container images and SBOMs still need proof. How we automate NIST 800-171 mapping: https://anchore.com/blog/how-to-automate-cmmc-compliance-for-containers-sboms/
0
0
0
0
Open post
Two versions of the same container image can look nearly identical. The vulnerability profile underneath usually isn't. Ben Lang shows how to compare versions directly using the Anchore Enterprise API.
https://anchore.com/blog/comparing-vulnerabilities-across-image-versions-anchore-enterprise-api
0
0
0
0
Open post
SBOMs are essential for "software archaeology." What did your build environment look like six months ago? Which past releases might be affected by a new vulnerability? This on-demand webinar explains why preserving lightweight SBOMs can answer these questions and provide critical historical context. #SBOM #Security #AppSec #DevSecOps
✅ See the power of historical SBOM data in action. Watch our expert webinar now: https://go.anchore.com/rapid-incident-response-with-sboms/
0
0
0
0
Open post
Anchore SBOM Score = CVSS + EPSS + KEV status 📊
Because not all vulnerabilities are created equal ⚠️
https://anchore.com/platform/sbom/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
0
0
0
0
Open post
@josh.bressers.name scanned 161 MCP containers. Found 9,000 vulnerabilities. 263 were critical.
"Software ages like milk, not wine." His analysis breaks down what's actually being deployed in the MCP ecosystem—and what to do about it.
https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
#MCP #ContainerSecurity
0
0
0
0
Open post
Compliance artifacts do not help during an active incident. Operational SBOMs do. We detailed a technical playbook to shift from reactive patching to strategic threat management using Anchore Enterprise. https://anchore.com/blog/zero-day-response-rapid-impact-assessment/
0
0
0
0
Open post
Point-in-time audits fail in Kubernetes because the infrastructure is ephemeral. We published a technical white paper on Compliance Operations. It covers integrating SBOM generation and continuous Cluster API polling to maintain an accurate state of running pods. https://anchore.com/blog/compliance-operations-making-kubernetes-audit-ready-by-design/
0
0
0
0
Open post
Your MCP server might be the weakest link—here's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/
0
0
0
0
Open post
False positives killing your team's productivity? 😵💫
Anchore Secure gives you signal, not noise 📡
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
0
0
0
0
Open post
Open source maintainers: drowning in a sea of "good first issues" that never get picked up? You're not alone.
It's a contributor time-shortage problem. Our Dir of DevRel @popey.me wondered if an AI could help. So he tried it.
Read to full post: https://anchore.com/blog/can-an-llm-really-fix-a-bug-a-start-to-finish-case-study/
0
0
0
0
Open post
Fleet-wide policy compliance in 1 query. Get registry → repo → tag → evaluations with a latest flag to filter stale results. Working Python included. Readd the hands-on technical walkthrough: https://anchore.com/blog/custom-reporting-graphql-via-anchore-enterprise-api/
0
0
0
0
Open post
Enforce continuous compliance. Supply chain security focus has increased 200%. The EU CRA requires lifecycle accountability. Shift left and centralize component visibility to eliminate bottlenecks, stay compliant by default, and ship secure software faster.
https://anchore.com/blog/eu-cra-vulnerability-management/
0
0
0
0
Open post
SBOM-first isn't just a buzzword—it's the architecture that makes continuous security actually possible 🔄
Feel the difference ⚡
https://anchore.com/platform/
#SBOM #CRA #SoftwareSupplyChain #Compliance
0
0
0
0
Open post
A vendor marks a CVE will_not_fix — do you include it in your zero-day sweep or filter it out? Ben Lang's latest on the Anchore Enterprise API covers both, plus the script to automate it. https://anchore.com/blog/chasing-zero-day-vulnerabilities-via-anchore-enterprise-api/
0
0
0
0
Remote instance
mstdn.business
Open on original server