Anchore Blog

Anchore Blog

2 SBOM & Supply Chain Security News Items to Watch
April 22, 2021 | We aren’t about to stop hearing about the need for a software bill of materials (SBOM) and software supply chains security anytime soon. You can expect more news about a Presidential executive order about SBOMs and a new software supply chain breach at Codecov that we’re all still learning more about. Read More >> 

Continuous Authority to Operate: The Realities and the Myths
April 15, 2021 | The Continuous Authority to Operate (cATO), sometimes known as the Rapid ATO, is becoming necessary as the DoD and civilian agencies are putting more applications and data in the cloud. Speed and agility are becoming increasingly critical to the mission as the government seeks new features and functionalities to support the warfighter and other critical US government priorities. Read More >> 

Software Supply Chain Security: Now is the Time to Act
April 8, 2021 | It’s time to make evaluating and mitigating software supply chain security risks at the top of mind as government agencies, corporations, industry analysts, and security firms try to chart a course forward for supply chain security after the SolarWinds hack. Read More >> 

Getting to Know and Love your Software Bill of Materials (SBOM)
March 12, 2021 | A DevOps to DevSecOps transformation works best with a structured framework acting as governance. When you approach such a transformation, putting structure around it allows you and your teams to stop, ask questions, and iterate on potential changes to your existing DevOps processes. Read More >> 

Creating a DevOps to DevSecOps Framework for your Organization
February 11, 2021 | A DevOps to DevSecOps transformation works best with a structured framework acting as governance. When you approach such a transformation, putting structure around it allows you and your teams to stop, ask questions, and iterate on potential changes to your existing DevOps processes. Read More >> 

Anchore Enterprise 3.0 Introduces New Features to Secure the Software Supply Chain
February 4, 2021 | Hopefully, heralding the start of what is a happier new year for everyone, today we are pleased to announce the availability of Anchore Enterprise 3.0. Over the past 18 months since our last major release, much has happened in the world of software security (and beyond!). Read More >> 

Introducing Anchore Enterprise 2.4
September 01, 2020 | Today, we are pleased to announce the GA of Anchore Enterprise 2.4. In keeping with previous releases in the 2.x series, version 2.4 has been heavily driven by customer requests both in terms of features and operational improvements. Without further ado, let’s go into the main enhancements. Read More >> 

Anchore Partners with Carahsoft
July 01, 2020 | When you want to sell to the government, it behooves you to pick your partners wisely—and it’s no accident that Anchore chose to work with the largest trusted government IT solutions provider, Carahsoft Technology Corporation, to distribute Anchore’s products to public sector customers.

Container Security for US Government Information Systems
May 08, 2020 | Over the last year, we received great feedback from our customers regarding our Container Security for US Government Information Systems white paper. Today, we are publishing version 2.0, which updates and expands upon last year’s document. Read More >>

Getting Started with Anchore Policy Bundles
May 5, 2020 | We aren’t about to stop hearing about the need for a software bill of materials (SBOM) and software supply chains security anytime soon. You can expect more news about a Presidential executive order about SBOMs and a new software supply chain breach at Codecov that we’re all still learning more about. Read More >> 

Building a DevSecOps Platform with the United States Air Force
May 01, 2020 | When I arrived at Anchore, I joined an amazing group of engineers working to turn a bunch of slides into a tangible reality for the US Air Force (USAF) and US Department of Defense (DoD). Read More >> 


Anchore Enterprise 2.3 Blog Series

Anchore Enterprise 2.3 Feature Series: Scheduled Reports
May 22, 2020 | With the release of Anchore Enterprise 2.3 (built upon Anchore Engine v0.7.1), we are happy to announce a new feature of our reporting service: the ability to run scheduled reports. Read More >>

Anchore Scanning for Windows Container Images
May 18, 2020 | With the recent release of version 2.3, Anchore Enterprise now supports scanning of Windows container images and the addition of a new feed source for identifying Windows vulnerabilities: Microsoft Security Response Center (MSRC). Read More >>

Anchore Enterprise 2.3 Feature Series: NuGet Package Support
May 14, 2020 | With the release of Anchore Engine 0.7.0 and Anchore Enterprise 2.3, we are happy to share that you can now scan for vulnerabilities in NuGet packages inside your container images. Read More >>

Anchore Enterprise 2.3 Feature Series: GitHub Security Advisories
May 07, 2020 | With the release of Anchore Enterprise 2.3 (built upon Anchore Engine v0.7.1), we are happy to announce a new feed provider: GitHub Security Advisories (GHSA). Read More >>

Introducing Anchore Enterprise 2.3
May 06, 2020 | Today, we announced the availability of Anchore Enterprise 2.3 for our enterprise and federal government customers. Read More >>