Container Vulnerability Scanning
Anchore Enterprise delivers:
- Vulnerability scanning for container images
- Less wasted time on false positives
- Faster, easier remediation
Why Choose Anchore Enterprise for Container Scanning
- Automated container image scanning
- Integrate with DevOps tools
- SBOM generation
- Fewer false positives
- Faster remediation
“Anchore gives us a centralized point with logging and metrics for a complete picture of our container security. We know exactly how many teams are scanning and what sort of images are failing.”
Find and fix vulnerabilities in your containers
Anchore Enterprise is a comprehensive solution for organizations with DevSecOps or compliance programs for software delivered in containers. It scans container images, generates an SBOM, identifies security vulnerabilities and other misconfigurations, and enables you to prioritize and remediate issues—even before they reach runtime.
Automate container image scanning
Automate vulnerability scanning and monitoring for containerized software. Perform scans across your CI/CD pipelines, image registries and repositories, and Kubernetes workloads — including base images and application containers. Identify malware, secrets, and other security risks.
Integrate with DevOps pipelines
100% API coverage and fully-documented APIs enable developers to work seamlessly in the tools they already use and identify known vulnerabilities in real-time. Automate scanning in source code repos, CI/CD pipelines, or container registries through native integrations. Streamline remediation of issues with notifications through GitHub, JIRA, Slack, and more.
Generate SBOMs automatically
Get an SBOM with a list of components for each container image and scan. Track changes over time to identify new or updated components. Based on your SBOM, get notified of new vulnerabilities.
Learn more about SBOM management with Anchore..
Reduce false positives
Optimize development velocity with an unparalleled signal-to-noise ratio. Get fewer false positives with vulnerability scan results that are pinpointed to a specific distro. Use flexible policies to prioritize based on severity or availability of a fix. Provide “corrections” and “hints” that improve results going forward. Add vulnerabilities to allowlists to prevent ongoing alerts.
Accelerate remediation
Fix vulnerabilities more quickly with Anchore Enterprise’s remediation recommendations. Specify when issues must be fixed with time-based allowlists. Reduce manual work with workflows connected to your issue tracker or Slack.
Container Vulnerability Scanning FAQs
How is Anchore Enterprise different than Syft and Grype?
Syft and Grype are open-source tools maintained by Anchore. Syft creates an SBOM and Grype identifies vulnerabilities in that SBOM. Anchore Enterprise is a comprehensive system to find, manage, and fix vulnerabilities and other security issues, like malware and secrets. Anchore Enterprise uses Syft and Grype as building blocks and extends them significantly with features that help you track SBOMs and vulnerabilities over time, apply rules and policies for compliance, manage false positives, and automate remediation workflows.
What are the vulnerability databases used by Anchore Enterprise?
Anchore Enterprise pulls vulnerability data from a variety of publicly available vulnerability data sources including:
- Alpine Linux SecDB: https://secdb.alpinelinux.org/
- Amazon Linux ALAS: https://alas.aws.amazon.com/AL2/alas.rss
- RedHat RHSAs: https://www.redhat.com/security/data/oval/
- Debian Linux CVE Tracker: https://security-tracker.debian.org/tracker/data/json
- Github GHSAs: https://github.com/advisories
- National Vulnerability Database (NVD): https://nvd.nist.gov/vuln/data-feeds
- Oracle Linux OVAL: https://linux.oracle.com/security/oval/
- RedHat Linux Security Data: https://access.redhat.com/hydra/rest/securitydata/
- Suse Linux OVAL: https://ftp.suse.com/pub/projects/security/oval/
- Ubuntu Linux Security: https://people.canonical.com/~ubuntu-security/
Documentation on vulnerability feeds in Anchore Enterprise
Which container platforms does Anchore Enterprise support for vulnerability scanning?
Anchore Enterprise integrates with all major container-based environments, including Kubernetes, Docker, and leading cloud container services such as Amazon EKS/ECR, Azure AKS/ACR, and Google GKE/Artifact Registry. If your workflow builds, stores, or runs container images, Anchore can scan it.
Does Anchore Enterprise scan more than just software packages?
Yes, Anchore Enterprise scans a container image to find all of the components across the entire file system, including the OS and open-source packages, the metadata associated with every file, and can even look inside the contents of files for malware or exposed secrets. Anchore Enterprise even cracks open archive files (like jars) to find components nested multiple layers down. Once all of the components have been cataloged, Anchore Enterprise identifies all of the relevant vulnerabilities.
How does Anchore handle false positives or false negatives?
To help with false negatives, Anchore Enterprise includes a “Hints” feature that allows developers to explicitly describe content in their applications to improve matches to enable vulnerability matching. This is particularly useful for teams which compile and install their own binaries. The Corrections feature allows security teams to correct misidentified metadata (for example where the version may be incorrect) to avoid false positives. Anchore also provides a feed of data which contains a list of ambiguous or incorrect vulnerability data which prevents false positives across all deployments.
What is a container scanner?
Container security scanning tools streamline software supply chain security and policy enforcement by scanning container images and their contents to identify vulnerabilities before they are deployed to production environments.
Learn more about container scanning
A Complete Guide to Container Security
Complete Guide to Hardening Containers with STIG
A Guide to Vulnerability Scanning with Open Source Tools
Speak with our security experts
Learn how Anchore’s SBOM-powered platform can help secure your software supply chain.