Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

anchore@mstdn.businessA

anchore@mstdn.business

@anchore@mstdn.business
About
Posts
27
Topics
27
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • MCP is having a moment.
    anchore@mstdn.businessA anchore@mstdn.business

    MCP is having a moment. @josh.bressers.name wanted to know: what are we actually shipping?

    9,000 vulns
    263 critical findings
    36K+ NPM packages
    Outdated base images

    Not fear-mongering—just data-driven reality. Read his analysis: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/

    #MCP #ContainerSecurity

    Uncategorized mcp containersecuri

  • EU CRA requires 24-hr exploit reporting by Sept 2026.
    anchore@mstdn.businessA anchore@mstdn.business

    EU CRA requires 24-hr exploit reporting by Sept 2026. Can you locate vulnerable K8s pods that fast? Anchore CompOps automates real-time CVE tracking & SBOM generation to keep you audit-ready. Read our white paper: https://anchore.com/white-papers/making-kubernetes-continuously-audit-ready-with-compops/

    Uncategorized

  • How to add vulnerability scanning to developer tools?
    anchore@mstdn.businessA anchore@mstdn.business

    How to add vulnerability scanning to developer tools?

    @RepoFlow's pattern:

    1. Generate SBOMs with Syft
    2. Scan SBOMs with Grype
    3. Parse JSON, deduplicate CVEs
    4. Display in existing UI

    Security without friction: https://anchore.com/blog/security-without-friction-how-repoflow-created-a-devsecops-package-manager-with-grype/

    Uncategorized

  • 🚀 New hardened container companies are launching constantly.
    anchore@mstdn.businessA anchore@mstdn.business

    🚀 New hardened container companies are launching constantly.

    The reason isn't compliance mandates—it's practical necessity.

    When scanners got accurate, the vulnerability problem became impossible to ignore. Hardened images are the efficient solution.

    Link Preview Image
    Hardened Images are Here to Stay | Anchore

    Learn why the demand for hardened containers is rising and how they address compliance and security challenges.

    favicon

    Anchore (anchore.com)

    Uncategorized

  • 🚨 The EU just made SBOMs mandatory for all software products!
    anchore@mstdn.businessA anchore@mstdn.business

    🚨 The EU just made SBOMs mandatory for all software products!

    Our guide breaks down the Cyber Resilience Act requirements and provides a roadmap to compliance before the 2027 deadline.

    Don't wait—start building your SBOM strategy today.

    🔗 https://anchore.com/sbom/eu-cra/

    #SBOM #CRA

    Uncategorized sbom cra

  • Your MCP server might be the weakest link—here's the data.
    anchore@mstdn.businessA anchore@mstdn.business

    Your MCP server might be the weakest link—here's the data. @josh.bressers.name scanned 161 MCP images and found 9,000 vulns / 263 criticals. Read the breakdown and fixes: https://anchore.com/blog/analyzing-the-top-mcp-docker-containers/

    #MCP #SoftwareSupplyChain #ContainerSecurity #DevSecOps

    Uncategorized mcp softwaresupplyc containersecuri devsecops

  • Container images bundle application code with underlying operating system dependencies.
    anchore@mstdn.businessA anchore@mstdn.business

    Container images bundle application code with underlying operating system dependencies. This introduces hidden vulnerabilities. Securing this supply chain requires granular insights and automated policy enforcement.

    See how it maps to DoW RMF:
    https://anchore.com/wp-content/uploads/2026/04/WP2026_The-Practitioners-Guide-Mapping-Container-Inspection-to-DoW-RMF-Controls.pdf

    #CyberSecurity #Containers #DevOps

    Uncategorized cybersecurity containers devops

  • Point-in-time audits fail in Kubernetes because the infrastructure is ephemeral.
    anchore@mstdn.businessA anchore@mstdn.business

    Point-in-time audits fail in Kubernetes because the infrastructure is ephemeral. We published a technical white paper on Compliance Operations. It covers integrating SBOM generation and continuous Cluster API polling to maintain an accurate state of running pods. https://anchore.com/blog/compliance-operations-making-kubernetes-audit-ready-by-design/

    Uncategorized

  • How do you secure an OS that relies on continuous rolling releases?
    anchore@mstdn.businessA anchore@mstdn.business

    How do you secure an OS that relies on continuous rolling releases? 🤔 Rather than using traditional molds, Anchore 5.26 features new matching logic engineered specifically to track Arch Linux updates & SecureOS configurations. https://anchore.com/blog/anchore-enterprise-5-26/

    Uncategorized

  • Don't let compliance checks hold up your delivery pipeline.
    anchore@mstdn.businessA anchore@mstdn.business

    Don't let compliance checks hold up your delivery pipeline. Automate your go/no-go decisions! 🚦

    Read Anchore Solutions Architect Chadd Owen's latest post on securing the DoD software factory and automating required gates: https://anchore.com/blog/anchore-enterprise-and-the-dod-devsecops-reference-design/

    #DevSecOps #ContainerSecurity

    Uncategorized devsecops containersecuri

  • "Bring Your Own SBOM" sounds simple...
    anchore@mstdn.businessA anchore@mstdn.business

    "Bring Your Own SBOM" sounds simple...

    Until you try to manage thousands of them 📊

    Scale is everything 📈

    https://anchore.com/platform/sbom/

    #SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

    Uncategorized softwaresupplyc sbom cybersecurity compliance devsecops

  • Stop settling for vulnerability feeds that don't understand your specialized infrastructure.
    anchore@mstdn.businessA anchore@mstdn.business

    Stop settling for vulnerability feeds that don't understand your specialized infrastructure. Anchore Enterprise 5.26 brings dedicated feeds for Fedora & VMware PhotonOS.

    See whats new 👇
    https://anchore.com/blog/anchore-enterprise-5-26/

    Uncategorized

  • We just launched our new SBOM Learning Hub, a library of resources for your dev and sec teams:🔹 SBOM 101 & formats🔹 Automating CI/CD integration🔹 Tackling data sprawl🔹 Surviving EU CRA & SSDF
    anchore@mstdn.businessA anchore@mstdn.business

    We just launched our new SBOM Learning Hub, a library of resources for your dev and sec teams:
    🔹 SBOM 101 & formats
    🔹 Automating CI/CD integration
    🔹 Tackling data sprawl
    🔹 Surviving EU CRA & SSDF

    Bookmark the hub 👇
    https://go.anchore.com/introduction-to-sboms.html?utm_source=sbom-campaign&utm_medium=social&utm_campaign=2026-04

    #DevSecOps

    Uncategorized devsecops

  • High-velocity pipelines make manual container inspection impossible, causing information overload and security gaps.
    anchore@mstdn.businessA anchore@mstdn.business

    High-velocity pipelines make manual container inspection impossible, causing information overload and security gaps. To address this, we created a guide to help ISSMs & ISSOs automate compliance.

    What it contains:
    📦 A breakdown of container architecture & defense
    ⚙️ Methods for automating compliance using policy-as-code
    🗺️ A direct mapping of container inspections to NIST 800-53 controls

    https://anchore.com/wp-content/uploads/2026/04/WP2026_The-Practitioners-Guide-Mapping-Container-Inspection-to-DoW-RMF-Controls.pdf

    Uncategorized

  • Compliance is no longer a paper exercise—it's a data challenge.
    anchore@mstdn.businessA anchore@mstdn.business

    Compliance is no longer a paper exercise—it's a data challenge.

    KubeCon EU 2026 made one thing clear: as regulations like the CRA and updated NIST frameworks tighten, the way we prove security must evolve. I recently joined two panels to dive into how we move past static spreadsheets into dynamic, automated security posture.
    If you're struggling to align engineering velocity with compliance requ... https://www.youtube.com/watch?v=UilEpsFPJTw
    https://www.youtube.com/watch?v=h5TCuLg35Cc

    #KubeCon #CloudNative #InfoSec #ComplianceAsCode

    Uncategorized kubecon cloudnative infosec complianceascod

  • False positives killing your team's productivity?
    anchore@mstdn.businessA anchore@mstdn.business

    False positives killing your team's productivity? 😵‍💫

    Anchore Secure gives you signal, not noise 📡

    Link Preview Image
    Anchore Secure: Container Security Solutions

    Ensure the security of software products you release or host as SaaS and provide SBOMs and assurance for your customers. Learn More>

    favicon

    Anchore (anchore.com)

    #SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps

    Uncategorized softwaresupplyc sbom cybersecurity compliance devsecops

  • Generating an SBOM is just step one.
    anchore@mstdn.businessA anchore@mstdn.business

    Generating an SBOM is just step one. How do we move past static lists to drive actual security decisions? Join SBOM architect Allan Friedman and Anchore CTO Zach Hill on April 21 to close the gap between open-source reality and enterprise security.

    https://go.anchore.com/the-challenges-of-third-party-software.html

    #SBOM #CyberSecurity

    Uncategorized sbom cybersecurity

  • The EU #CRA means SBOMs are no longer optional.
    anchore@mstdn.businessA anchore@mstdn.business

    The EU #CRA means SBOMs are no longer optional.

    ✅ Generate #SBOM in machine-readable format
    ✅ Include top-level dependencies
    ✅ Keep updated throughout product lifecycle
    ✅ Be ready by December 2027

    Get our complete compliance checklist:

    🔗 https://anchore.com/sbom/eu-cra/

    Uncategorized cra sbom

  • "The format doesn't really matter...
    anchore@mstdn.businessA anchore@mstdn.business

    "The format doesn't really matter... It's really about the content."

    We hosted @stevespringett, Chair of the CycloneDX WG, to discuss why the industry needs to stop fighting format wars and start focusing on data utility.

    Read the 4 lessons: https://anchore.com/blog/4-lessons-on-future-of-software-transparency-with-steve-springett/

    Uncategorized

  • @joshbressers: "If you can't search your past builds, you can't bound your blast radius.
    anchore@mstdn.businessA anchore@mstdn.business

    @joshbressers: "If you can't search your past builds, you can't bound your blast radius. SBOMs turn a frantic morning into a simple query."

    His zero-day incident response story from inside Anchore's response to the NPM supply chain attack:

    https://anchore.com/blog/a-zero-day-incident-response-story-from-the-watchers-on-the-wall/

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups