Supply Chain SecuritySoftware Composition Analysis (SCA)SBOM Management

Deep container image inspection and SBOM generation for supply chain security

Anchore featured image

Product Overview

14 Integrations

Anchore provides comprehensive software supply chain security through deep container image analysis and policy enforcement. The platform performs detailed vulnerability scanning of container images, analyzing all layers to identify security issues in operating system packages, application dependencies, and custom code. Anchore's powerful policy engine allows organizations to define and enforce custom security policies, automatically blocking deployment of images that violate compliance or security requirements. The platform integrates seamlessly with CI/CD pipelines including Jenkins, GitLab, GitHub Actions, and CircleCI to catch issues early in the development process. Anchore supports Kubernetes admission webhooks for deployment-time policy enforcement, preventing non-compliant containers from running in production clusters. The platform generates detailed Software Bill of Materials (SBOM) in multiple formats (SPDX, CycloneDX) for complete supply chain transparency and compliance. Advanced features include secret detection to identify exposed credentials, license compliance checking, malware scanning, and registry synchronization for continuous monitoring. Based on the popular open-source Anchore Engine, the enterprise platform adds role-based access control (RBAC), detailed audit reporting, multi-tenancy, and enterprise-grade support. Anchore helps organizations meet compliance requirements for NIST, SSDF, and executive orders on software supply chain security.

Product Details

Security Domain

Primary security domain

Supply Chain Security

Key Capabilities

Specific security problems this product solves

SBOM ManagementSoftware Composition Analysis (SCA)

Key Features

Core capabilities and differentiators

Admission WebhooksCI/CD IntegrationContinuous Vulnerability ScanningCustom PoliciesDeep Image ScanningLicense ComplianceMalware ScanningPolicy EngineRegistry MonitoringSBOM GenerationSecret Detection

Integrations

Compatible tools and platforms

Amazon ECRAzure Container RegistryCircleCIGitHub ActionsGitLabGoogle Container RegistryHarborJenkinsJFrog ArtifactoryJiraKubernetesQuaySlackWebhook

Deployment Options

Where and how this solution can be deployed

CloudHybridOn-Premise

Pricing Model

How this solution is priced

Enterprise LicenseOpen SourceSubscription

Vendor Information

Anchore logo

Anchore

Santa Barbara, CA, USA