# anchore.com > AI-optimized mirror of anchore.com containing 50 pages totalling 177,183 words of clean markdown content, structured data, and semantic HTML. Original source: https://anchore.com/. Last updated: 2026-05-17T19:10:25.057Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [Control your supply chain risk. Stay compliant by default.](/site-root.html): Anchore's software supply chain solutions automate vulnerability scanning, strengthen container security, and support compliance with NIST, FedRAMP & more. (428 words) ## Articles & Blog Posts - [category/log4j/index.html](/category/log4j/index.html) (1 words) - [category/blog/culture/index.html](/category/blog/culture/index.html) (1 words) - [culture/mission-impact/index.html](/culture/mission-impact/index.html) (1 words) - [culture/humans-of-anchore/index.html](/culture/humans-of-anchore/index.html) (1 words) - [blog/guide-to-continuous-compliance-monitoring/index.html](/blog/guide-to-continuous-compliance-monitoring/index.html) (1 words) - [blog/index.html](/blog/index.html) (1 words) - [software-supply-chain-security/open-source-container-vulnerability-scanning-tools/index.html](/software-supply-chain-security/open-source-container-vulnerability-scanning-tools/index.html) (1 words) - [pricing/index.html](/pricing/index.html) (1 words) - [NIST CSF 2.0: Key Takeaways and Implementation Strategies](/compliance/nist/nist-csf-2/index.html): Learn what’s new with the CSF 2.0 Draft released by NIST in August,and get expert tips from the team at Anchore on implementation strategies. (1,424 words) - [Anchore Continues Expansion into Software Supply Chain Security Market](/press/anchore-continues-expansion-into-software-supply-chain-security-market.html): New customer adoption and open source community involvement fuel expansion Santa Barbara, Calif - January 28, 2022 - Anchore today announced strong results in the software supply chain security market over the last year. With concerns about the security of the software supply chain driving demand for automated tooling and… (1,178 words) - [A Zero-day Incident Response Story from the Watchers on the Wall](/blog/a-zero-day-incident-response-story-from-the-watchers-on-the-wall.html): Learn about the npm supply chain attack and the response to zero-day vulnerabilities in the software community. (2,219 words) - [Enforce software container compliance.](/container-compliance/index.html): Automate compliance checks with custom and out-of-the-box policies for federal or enterprise environments. Find Out More > (539 words) - [A Guide to FedRAMP: FAQs & Key Takeaways](/fedramp/fedramp-overview/index.html): Everything you need to know about FedRAMP; how to get certified, an overview of impact levels, and tips and tools to make the process easier. (4,645 words) - [From War Room to Workflow: How Anchore Transforms CVE Incident Response](/blog/from-war-room-to-workflow-how-anchore-transforms-cve-incident-response.html): Learn how Anchore Enterprise transforms Kubernetes vulnerability management from chaotic war rooms to streamlined workflows for critical CVEs like #IngressNightmare. (1,694 words) - [How to Automate Container Vulnerability Scanning for Harbor Registry with Anchore Enterprise](/blog/how-to-automate-container-vulnerability-scanning-for-harbor-registry-with-anchore-enterprise.html): Learn how to automate container vulnerability scanning with Harbor Registry by integrating Anchore Enterprise. Secure your software supply chain without sacrificing development velocity. (1,396 words) - [Container Vulnerability Scanning](/container-vulnerability-scanning/index.html): An API-friendly container scanner to identify vulnerabilities in container images with fewer false-positives and faster remediation. Find out more > (1,172 words) - [container-vulnerability-scanning-test/index.html](/container-vulnerability-scanning-test/index.html) (1 words) - [Software Supply Chain Security](/open-source-security/index.html): Improve open source security by easily tracking direct and transitive open source dependencies to identify and fix vulnerabilities early. (648 words) - [False Positives and False Negatives in Vulnerability Scanning: Lessons from the Trenches](/blog/false-positives-and-false-negatives-in-vulnerability-scanning.html): Learn about the critical balance of false positives and false negatives in security. Improve your vulnerability detection strategy. (1,405 words) - [A Guide to Air Gapping: Balancing Security and Efficiency in Classified Environments](/blog/dod-devsecops-air-gap-environment/index.html): Learn how air gapping enhances security for DevSecOps in DoD environments. Discover Anchore's solutions for protecting classified data > (1,272 words) - [Anchore Expands Federal Footprint with $1.58M Tactical Funding Contract Award](/press/anchore-expands-federal-footprint-with-1-58m-tactical-funding-contract-award.html): Recent contract, new customer installations, and marketplace listings further advance Anchore’s presence in the federal market. Santa Barbara, CA – October 27, 2022 - Today Anchore announced a $1.58M tactical funding award to extend its Small Business Innovation Research (SBIR) Phase II contract with the United States Air Force (USAF)… (716 words) - [A Policy Based Approach to Container Security & Compliance](/blog/policy-based-compliance-approach-to-container-security.html): In this post we will first define compliance, and then cover a few steps development teams can take to help to bolster their container security. (1,151 words) - [Explore Roles and Responsibilities at Anchore](/culture/be-yourself-with-us/index.html) (945 words) - [Considerations for your FedRAMP Compliance Checklist](/category/fedramp/index.html) (1,131 words) - [Cybersecurity Awareness Month no longer works](/blog/cybersecurity-awareness-month-no-longer-works/index.html): October is Cybersecurity Awareness Month, an idea that's more than 20 years old now. It's an idea that had its day, it's time to re-think the intended purpose. Cybersecurity is ever present now; Cybersecurity Awareness Month shouldn't exist anymore. The modern purpose of Cybersecurity Awareness Month seems to be mostly… (925 words) - [NIST SP 800-190: Overview & Compliance Checklist](/compliance/nist/800-190/index.html): Get to know NIST SP 800-190, how it differs from other cybersecurity frameworks, and a checklist for achieving and maintaining compliance. (1,611 words) - [Continuous security checks directly in your container image registry.](/container-registry-scanning/index.html): Ensure organization-wide security and compliance for registry auditing in a complete security platform built for developers. Learn More > (495 words) - [Anchore and Chainguard Partner to Deliver Next-Generation Supply Chain Security](/press/chainguard-partnership-supply-chain-security/index.html): Discover how container security is enhanced through Chainguard and Anchore's strategic partnership for safer software deployment. (744 words) - [Anchore Secure](/platform/secure/index.html): Ensure the security of software products you release or host as SaaS and provide SBOMs and assurance for your customers. Learn More> (1,090 words) - [Anchore Extends Best-in-Class Container Security Offering with Bring Your Own SBOM Support](/press/anchore-releases-bring-your-own-sbom/index.html): Anchore Enterprise is a powerful, cost-effective, and compliant management, monitoring, and automation tool for understanding and securing complex software supply chains. SANTA BARBARA, CA – May 21, 2025 – Anchore, the market leader in software composition analysis for cloud native platforms, today announced the next phase of its SBOM strategy… (663 words) - [Anchore Enterprise and the DoD DevSecOps Reference Design](/category/datasheets/index.html) (761 words) - [Anchore Survey Shows Only 1 in 5 Organizations Have Full Visibility into Their Open Source Software Components](/press/anchore-survey-shows-only-1-in-5-organizations-have-full-visibility-into-their-open-source-software-components.html): The survey highlights that 78% plan to increase their use of SBOMs. Compliance drives hardening the software supply chain as organizations must meet 4.9 government regulations and standards on average.  Santa Barbara, CA – November 7, 2024 - Anchore today released its third report of executive insights into managing software supply… (653 words) - [NPM Supply Chain Breach Response for Anchore Enterprise and Grype Users](/blog/npm-supply-chain-breach-response-for-anchore-enterprise-and-grype-users.html): On September 8, 2025 Anchore was made aware of an incident involving a number of popular NPM packages to insert malware. The technical details of the attack can be found in the Aikido blog post: npm debug and chalk packages compromised After an internal audit, Anchore determined no Anchore products,… (379 words) - [Anchore Unveils New Open Source Tools For Automated DevSecOps Pipeline Security](/press/anchore-unveils-new-open-source-tools-for-automated-devsecops-pipeline-security.html): Anchore launches a collection of new open source tools for automating DevSecOps pipeline security and analysis—introducing Syft and Grype. (525 words) - [FedRAMP Pre-Assessment Playbook for Containers](/category/playbooks/index.html) (755 words) - [Anchore Delivers Hardened Version of Policy-Based DevSecOps Platform to the DoD](/press/20200624-dod-hardened-containers/index.html): Anchore Federal has reached the criteria for hardened applications that adhere to the United States Department of Defense’s (DoD) security and compliance requirements, allowing the software to be used in security-sensitive DoD projects (494 words) - [Software Supply Chain Security Tools for Modern DevSecOps](/software-supply-chain-security/index.html): Anchore’s end-to-end, SBOM-powered software supply chain security platform makes it easier than ever to prevent and remediate attacks. (1,172 words) - [CI/CD Security & Compliance](/cicd/index.html): Embed security and compliance checks into your CI/CD pipeline with an API-friendly solution. Learn More > (516 words) - [Kubernetes Image Scanning](/kubernetes/index.html): Scan images against security policies before deployment and while running in Kubernetes. Learn about Kubernetes vulnerability scanning > (474 words) - [Cisco Umbrella](/category/case-studies/index.html) (180 words) - [A Guide for Developers, Security Engineers & the DevSecOps Community](/category/ebook/index.html) (10 words) - [Experts say software’s shrug at security is over, thanks to the EU’s Cyber Resilience Act](/press/experts-say-softwares-shrug-at-security-is-over-thanks-to-the-eus-cyber-resilience-act.html): Anchore's Josh Bressers on the EU's Cyber Resilience Act and the value of enforcing mandatory cybersecurity standards. Read more. (60 words) - [Anchore: Keeping Your Code Shipshape with SBOMs!](/press/anchore-keeping-your-code-shipshape-with-sboms/index.html): See the full segment with Truth in IT here.   (39 words) - [Introduction](/category/solution-guide/index.html) (42 words) - [Reports Archives | Anchore](/category/reports/index.html) (41 words) - [The Actionable Framework for Software Supply Chain Security](/category/events/index.html) (8 words) - [**Start with the Hardened Images and keep them that way**](/category/blog/index.html) (105,532 words) - [Best Practices](/category/kubernetes/index.html) (8,592 words) - [**Start with the Hardened Images and keep them that way**](/author/teamanchore/index.html) (29,450 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/content/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/content/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/content/robots.txt): Crawler directives