Anchore Enterprise v6.2 is out today. The EU Cyber Resilience Act's (CRA) 24-hour vulnerability reporting window went into effect September 11, 2026. At the same time, AI models are becoming part of the software supply chain: GGUF files, Docker Models, multi-gigabyte weights that most scanners never touch. This release adds: * Native AI model detection to your SBOM catalog * A new Anchore Enterprise MCP Server for AI agent integration * VEX-aware policy evaluation * Outcome-change notifications * Severity-based package filtering Read the release blog: https://lnkd.in/g3cXGR-9 #SoftwareSupplyChain #SBOM #CyberResilienceAct #DevSecOps
Anchore
Software Development
Santa Barbara, CA 4,594 followers
The first SBOM-powered SCA platform to deliver continuous software supply chain security.
About us
Anchore is a leader in software supply chain security for modern cloud-native environments. Our SBOM-powered software composition analysis embeds continuous security and compliance checks at every stage of the software development process for early detection. Large enterprises and government agencies use Anchore Enterprise to create comprehensive software bills of materials, improve container security, automate vulnerability scanning, enable continuous visibility, and enforce compliance with government and industry standards like NIST, FedRAMP, EU CRA, and more.
- Website
-
http://www.anchore.com/
External link for Anchore
- Industry
- Software Development
- Company size
- 51-200 employees
- Headquarters
- Santa Barbara, CA
- Type
- Privately Held
- Founded
- 2016
- Specialties
- Vulnerability Management, SBOM, Container Scanning, SSDF Compliance, FedRamp Compliance, Software Composition Analysis, DevSecOps, cATO, Secure DevOps, Policy Enforcement, SBOM Management, Container Security, CI/CD Pipeline Security, Federal Compliance, Kubernetes Images Scanning, Open Source Security, OSS License and Health Management, Software Supply Chain Security, Supply Chain Security , NIST Compliance, STIG Compliance, and Vulnerability Scanner
Employees at Anchore
Locations
-
Primary
Get directions
800 Presidio Ave
Suite B
Santa Barbara, CA 93101, US
Updates
-
🏆 Success in the defense sector requires unparalleled security measures. Read how #DreamFactory partnered with #AnchoreEnterprise to meet #DoD requirements, providing air-gapped vulnerability scans while maintaining #compliance. A must-read for anyone serving highly regulated industries! 🔗 https://lnkd.in/gs4FUFAi #DoDSoftwareFactory
-
-
AI models are officially part of your software supply chain—and your compliance surface. Arriving alongside the September 11 EU Cyber Resilience Act (CRA) enforcement deadline, our latest briefing introduces Anchore Enterprise v6.2, extending SBOM visibility directly into AI models (GGUF, Docker Models) and adding native MCP support for AI security agents. Inside this edition: - Anchore Enterprise v6.2: Extending supply chain governance to AI models and AI agent workflows. - Zero-Day Forensics: What traditional scans miss the moment a new vulnerability drops. - In-Cluster K8s Vetting: Why registry scans leave major blind spots in runtime environments. - CISA’s 2026 SBOM Standard: How updated minimum element rules turn inventories into defensible audit trails. - Multi-Framework Compliance: Streamlining NIST, FedRAMP, CMMC, and CRA checks with a single SBOM. Read the full briefing and register for our upcoming STIG webinar: 👇 P.S. Navigating federal end-of-fiscal-year deadlines? Learn how teams are using remaining FY funds to automate ATO evidence and accelerate DevSecOps compliance.
-
December 7, 2026 is a real deadline now, and it's tied to your SBOM quality. On June 10, 2026, CISA issued Binding Operational Directive 26-04, replacing CVSS-based prioritization with 4 decision points: public exposure, KEV status, exploit automation, and technical impact. The worst combination carries a 3-day remediation clock. FedRAMP moved fast on it. Public Notice NTC-0014 (June 16, 2026) pulled mandatory adoption of the Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules up from June 2027 to December 7, 2026, with a corrective-action grace period to March 7, 2027. CISA supplies 3 of the 4 decision points through Vulnrichment: KEV status, exploit automation, technical impact. The fourth, exposure, is yours, and exposure is a function of your inventory. When a KEV lands with a 3-day clock, "are we running this component anywhere, including transitively" has to be a query, not a project. Full breakdown: https://lnkd.in/en8phk7e #FedRAMP #BOD2604 #SBOM #FederalCompliance
-
-
The standard security playbook for a new CVE looks something like this: the CVE is published, your environment is assessed, and the results are reviewed. This playbook assumes there is adequate time between disclosure and exploitation, which is increasingly less guaranteed. Our latest blog explains why reactively scanning for vulnerabilities is the wrong instinct now, and what querying an inventory you already have buys you instead. https://lnkd.in/ePu5GcEb
-
-
For #software to be built, deployed, and used by the warfighter, it must achieve ATO and be built on a platform that meets strict DoD standards. Learn how Anchore and Sigma Defense teamed up to help the US Navy in this case study 👉 https://lnkd.in/g3tNCVTe
-
-
The 2021 NTIA baseline described your software. CISA's 2026 Minimum Elements also describe the party making a claim about it. 7 of the 10 new elements are about the document, not the code: SBOM Author, SBOM Author Signature, Data Format Name, Data Format Version, Generation Context, Tool Name, Tool Version, and SBOM Version. Generation Context matters more than it looks. A pre-build SBOM sees declared dependencies. A post-build image scan sees installed packages. Those are different claims about different things, and for 5 years we've treated them the same. Now you have to say which one you ran. Signed, attributable, versioned. You know who produced the SBOM, with what tool, at what stage of the build, and which revision you're holding. We crosswalked all 23 elements against Anchore Enterprise. Full breakdown here: https://lnkd.in/en8phk7e #SBOM #SoftwareSupplyChain #DevSecOps #SPDX
-
-
Traditional STIG scanners need a shell to run their checks. Chainguard builds images without one, by design. That leaves DoD programs pursuing an ATO, and vendors pursuing FedRAMP, with a bad tradeoff: soften a hardened image just to pass a compliance scan, or maintain two separate STIG workflows depending on which image variant you're running. We're fixing that. Join Anchore and Chainguard on Sept 24 for a live demo of STIG checks running on shell-less Chainguard images, no shell execution required. Sign up: https://lnkd.in/ejuikhde #STIG #Chainguard #FedRAMP #ContainerSecurity
-
-
Google Cloud's Mandiant just published a number worth noting– the estimated mean time to exploit a vulnerability is now negative 7 days. This is reinforced by CrowdStrike's 2026 Global Threat Report, which states that 42% of vulnerabilities are exploited before public disclosure. This happened in real time in July: Microsoft shipped a fix for a critical SharePoint RCE on July 14th. It was already being exploited in the wild as a zero-day. CISA added it to the KEV catalog just 2 days later. Our latest blog covers what that means for reactively scanning for new vulnerabilities, and it's the third in our series on the real operational problems Anchore's product quickstarts solve. https://lnkd.in/ePu5GcEb
-
-
We start in an hour. EU CRA Article 14's 24-hour reporting deadline is tomorrow, September 11, 2026. If you're still working out what qualifies as reportable, how ENISA wants it submitted, or how to govern this beyond the deadline, join Dr. Andreas Kotulla (Bitsea GmbH) and Alex Rybak (Anchore) now. Last call: https://lnkd.in/eA45GyEd #CRA #ENISA #SoftwareSupplyChain
-