Anchore
What is Anchore?
Anchore is a software supply chain security and container image analysis platform (software supply chain security) that automates scanning, policy enforcement, and compliance workflows across containerized and cloud-native environments.
Show more
- Automated container image and artifact scanning for vulnerabilities and misconfigurations (vulnerability management)
- Policy-based governance for container images, registries, and Continuous Integration and Continuous Deployment (CI/CD) workflows (governance and compliance)
- Software Bill of Materials (BOM) generation and analysis for images and artifacts (SBOM management)
- Integration with CI/CD pipelines and container registries for pre-deployment checks (DevSecOps integration)
- Reporting and audit support for regulatory and internal compliance requirements (compliance reporting)
More About Anchore
Anchore focuses on software supply chain security (software supply chain security) and container image analysis (container security), addressing the need for automated controls over what software artifacts are built, stored, and deployed into production environments. It targets organizations that build and operate containerized and cloud-native applications and need to maintain security, compliance, and governance across complex pipelines and registries.
At its core, Anchore provides scanning capabilities (vulnerability management) that inspect container images and related artifacts for known vulnerabilities, misconfigurations, and policy violations. These scans use Software Composition Analysis (SCA) to identify packages, dependencies, and metadata, and then compare them against vulnerability sources and compliance rules. Anchore also generates and manages Software Bills of Materials (SBOMs) (SBOM management), which catalog the components contained in images and artifacts for security review, license tracking, and audit purposes.
The platform embeds Policy as Code (PaC) capabilities (governance and compliance) that allow security and platform teams to define rules governing acceptable images, configurations, and component versions. These policies can enforce requirements such as vulnerability thresholds, base image standards, forbidden packages, and configuration constraints. Anchore integrates these checks directly into CI/CD pipelines (DevSecOps integration), so builds can be blocked or flagged when they fail defined policies before reaching production registries or runtime environments.
Anchore connects with container registries and artifact repositories (registry integration), enabling continuous monitoring of images already stored and in use. This supports ongoing vulnerability detection as new issues are disclosed, and helps teams track which workloads are associated with specific vulnerable components. Reporting and dashboards (security and compliance reporting) provide visibility into risk posture, policy compliance status, and remediation progress across projects and teams, supporting audit and regulatory requirements.
Architecturally, Anchore is built to operate in cloud-native environments (cloud-native security), with components that can be deployed within enterprise infrastructure and integrated with existing DevOps and security tooling. It is used by platform, security, and DevOps teams to centralize container image governance, reduce manual review in pipelines, and maintain an inventory of software components via SBOMs. In an enterprise directory, Anchore fits within categories such as software supply chain security, container security, vulnerability management, and DevSecOps tooling.