Le Lézard
Classified in: Transportation, Science and technology
Subject: PDT

Anchore Demonstrates How to Further Software Supply Chain Security with Signed SBOMs and Security Reports


SANTA BARBARA, Calif., Sept. 20, 2021 /PRNewswire/ -- Anchore, a leader in software supply chain security, today introduced a demonstration workflow that shows how software producers can create, sign, and share accurate software bill-of-material (SBOM) and security reports to help further the security of software supply chains. As the United States government implements the Executive Order on Improving the Nation's Cybersecurity, federal agencies expect to require SBOMs from their software vendors. Commercial enterprises can also benefit from verifiable documents that attest to the contents and security status of the software they use.

The demonstration workflow leverages open source tools Syft, Grype, and Sigstore's Cosign to create and share signed attestations about the security of software applications delivered in containers.

The workflow details how software producers can:

Software users can then verify the software container image, SBOM, and vulnerability report for an accurate picture of both the contents and security status of the software they are using.

The demonstration workflow was developed in partnership with Sigstore and builds off the complementary capabilities of open source tools, Syft, Grype, and Sigstore's Cosign. A detailed blog on how to implement this demonstration workflow is available here and sample code and documentation is available here.

Why Software Supply Chain Security is Important
The need for a secure software supply chain increases in priority and urgency each day due to continued and persistent cyberattacks. The widespread use of DevOps processes to speed cloud-native software development has led to a concurrent rise in the use of software containers. An Anchore survey of 400+ large enterprises showed that 65% of respondents have a significant number of applications running in containers.

Containers make it easy to package software during development, but can bring in multiple open source software (OSS) dependencies as applications move through the DevOps pipeline, creating new security requirements. As a result, 63% of survey respondents plan to increase container use and 60% report improving supply chain security as a top initiative.

Anchore and Sigstore Cosign engineers are working in tandem to educate the open source community and raise industry awareness of software supply chain security and available tools to proactively secure the development pipeline. More information about SBOMs and the importance of container attestation for SBOM signing is available in this blog post.

About Anchore
Anchore is a leader in software supply chain security and enables organizations to protect cloud-native applications against software supply chain attacks. Anchore technology embeds continuous security and compliance checks at every stage of the software development process to prevent security risks from reaching production. Large enterprises and government agencies use Anchore solutions to generate a comprehensive software bill of materials, pinpoint vulnerabilities, identify malware and discover unprotected credentials that can lead to hacks and ransomware. With an API-centric approach, Anchore solutions integrate into the tools developers already use to detect issues earlier, saving time and lowering the cost to fix vulnerabilities. To learn more visit www.anchore.com.

Media contact:
Brandie Gerrish
[email protected]

SOURCE Anchore


These press releases may also interest you

at 19:27
ShipSaving, a fast-growing shipping platform recognized in the 2023 Deloitte Technology Fast 500tm, proudly announces a groundbreaking development as the first multi-carrier shipping company to offer UPS no-label shipping. This innovative feature...

at 19:05
Takeda (TSE:4502/NYSE:TAK) today announced that the U.S. Food and Drug Administration (FDA) has approved ENTYVIO® (vedolizumab) subcutaneous (SC) administration for maintenance therapy in adults with moderately to severely active Crohn's disease (CD)...

at 18:52
In celebration of Miami Tech Month, the city of Miami is hosting a variety of events, welcoming venture capitalists, entrepreneurs, and technology innovators from around the globe. During this week, the city hosted Startup OLÉ, one of Europe's...

at 18:25
Skyhigh Security today announced it was named a Visionary in the 2024 Gartner® Magic Quadranttm for the second year in a row for its Security Service Edge (SSE) portfolio. The Magic Quadrant evaluates vendors based on their Ability to Execute and...

at 18:15
After a rigorous RFP process, the system of the Higher Colleges of Technology (HCT) has selected the YuJa Enterprise Video Platform to serve more than 23,000 students and 2,000 staff at its 17 modern, technology-enhanced campuses in the United Arab...

at 17:46
CASETiFY, the global tech accessory brand loved by millennials, Gen Z, and Hollywood celebrities, announces today its newest collection that caters to the diverse charging requirements of today's cutting-edge technology. With a mission to ensure that...



News published on and distributed by: