
Anchore
Software composition analysis with continuous vulnerability monitoring and SBOM management for containers.
Vendor Information
Anchore Overview
Anchore delivers an Software Bill of Materials (SBOM)-powered software composition analysis platform providing end-to-end container security and software supply chain management for cloud-native environments. Unlike traditional vulnerability scanners that perform point-in-time scans, Anchore generates and stores comprehensive SBOMs for every container image, enabling continuous monitoring for new vulnerabilities without rescanning or requiring access to original artifacts, while providing historical forensics to determine if deployed software was ever susceptible to newly discovered vulnerabilities.
The platform features deep container image analysis examining all layers to identify vulnerabilities in operating system packages, application dependencies, and custom code, with support for secret detection, malware scanning, and license compliance checking. Anchore integrates seamlessly into Continuous Integration/Continuous Delivery (CI/CD) pipelines including Jenkins, GitLab, GitHub Actions, and CircleCI for shift-left security, while supporting Kubernetes admission webhooks for deployment-time policy enforcement preventing non-compliant containers from reaching production clusters, with the powerful policy engine allowing custom security policies based on flexible criteria.
Founded in 2015 and headquartered in Santa Barbara, Anchore serves flagship customers including NVIDIA, Cisco, United States Navy, and Department of Defense who rely on its SBOM-centric approach for meeting Federal Risk and Authorization Management Program (FedRAMP), National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF), and executive order requirements on software supply chain security. The platform generates SBOMs in multiple industry-standard formats including Software Package Data Exchange (SPDX) and CycloneDX, with the open-source Syft and Grype tools maintained by Anchore providing community-driven SBOM generation and vulnerability scanning capabilities.
Key Capabilities
Standardized capabilities mapped to this product's security niche
Scans images stored in registries (ECR, GCR, Artifact Registry, Docker Hub), for vulnerable OS packages and application dependencies at push time or on schedule, without requiring a running container.
Identifies OSS licenses in the dependency tree and flags conflicts with the project's target license or policy (GPL contamination, copyleft obligations, export-controlled components). Separate from vulnerability detection.
Identifies packages with known-malicious behavior (typosquatting, dependency confusion, backdoored releases), distinct from packages with CVEs in legitimate code.
Security rules defined as code, versioned in SCM, and evaluated automatically at every scan. Enforces consistent policy across all repositories without manual configuration per project.
Blocks or flags PRs in CI/CD pipelines based on policy-defined thresholds, configurable by severity, CVSS score, exploitability, fix availability, or CVE age. Prevents vulnerable code from merging without requiring zero-tolerance policies.
Exports the dependency inventory as a machine-readable Software Bill of Materials in SPDX or CycloneDX format, consumable by downstream vulnerability scanners, compliance tools, and procurement workflows.
Identifies hardcoded credentials, API keys, tokens, and private keys in source files. Operates on the repository and commit history, not at runtime.
Traverses the full dependency graph to surface CVEs in indirect dependencies, packages required by your direct dependencies. Direct-only scanning misses the majority of vulnerable code paths in modern polyglot projects.
Integrations
Compatible tools and platforms
Solution Details
Deployment Options
Where and how this solution can be deployed
Support Channels
Available support and communication options
Pricing Model
How this solution is priced
How to buy
This profile hasn’t been claimed yet. Contact the vendor directly for pricing and purchasing options.
Is this your company?
Claim Your Profile