# anchore

Published articles for anchore.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run

DevFeed: [Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run](<https://devfeed.tech/articles/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run-13123.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run>)

Published: 2026-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [apache](<https://devfeed.tech/tags/apache.md>), [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cinc-auditor](<https://devfeed.tech/tags/cinc-auditor.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>)

### AI overview

Chainguard introduces a ready-to-run cinc-auditor container image for STIG scanning of Chainguard Containers. The image includes a maintained GPOS SRG InSpec profile, removes separate profile and dependency setup, and supports production compliance pipelines, including FedRAMP workflows.

### Source excerpt

Chainguard launches a ready-to-run STIG scanner with a built-in GPOS SRG InSpec profile, simplifying compliance scans for containers and FedRAMP workflows.

## How Chainguard Automated Detection and Patching of a High-Severity CVE

DevFeed: [How Chainguard Automated Detection and Patching of a High-Severity CVE](<https://devfeed.tech/articles/this-shit-is-hard-the-life-and-death-of-a-cve-in-the-chainguard-factory-13291.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-the-life-and-death-of-a-cve-in-the-chainguard-factory>)

Published: 2026-02-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [grype](<https://devfeed.tech/topics/grype.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cve-remediation](<https://devfeed.tech/tags/chainguard-cve-remediation.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci](<https://devfeed.tech/tags/ci.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [github](<https://devfeed.tech/tags/github.md>), [grype](<https://devfeed.tech/tags/grype.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article describes how Chainguard's Factory detected a high-severity vulnerability affecting k9s, updated Grype, opened and merged a pull request, and published a fixed package within 46 hours of the advisory. It also reports that Chainguard remediated 2,960 unique CVEs in November 2025 while meeting its stated remediation SLA.

### Source excerpt

The Chainguard Factory and DriftlessAF automate CVE detection and patching, delivering fixes in hours and maintaining industry-leading remediation SLAs.

## Anchore Enterprise now validates Chainguard Libraries: prevent 98% of Python malware and eliminate high-severity CVE toil

DevFeed: [Anchore Enterprise now validates Chainguard Libraries: prevent 98% of Python malware and eliminate high-severity CVE toil](<https://devfeed.tech/articles/anchore-enterprise-now-validates-chainguard-libraries-prevent-98-of-python-malware-and-eliminate-high-severity-cve-toil-12872.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/anchore-enterprise-now-validates-chainguard-libraries>)

Published: 2025-12-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Python](<https://devfeed.tech/topics/python.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-chainguard](<https://devfeed.tech/tags/anchore-chainguard.md>), [anchore-chainguard-partnership](<https://devfeed.tech/tags/anchore-chainguard-partnership.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [malware](<https://devfeed.tech/tags/malware.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [python](<https://devfeed.tech/tags/python.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Anchore Enterprise now supports scanning and validating Chainguard Libraries for Python. The integration combines Anchore's supply-chain security enforcement with Python libraries built from source in a tamper-proof, SLSA L2-certified environment with provenance and signed SBOMs, aiming to prevent malware introduced during build or distribution and reduce high-severity CVE remediation effort.

### Source excerpt

Customers can now leverage Anchore Enterprise's scanning capabilities for Chainguard Libraries for Python.

## Introducing Our Newest Ecosystem Integration: Anchore Enterprise

DevFeed: [Introducing Our Newest Ecosystem Integration: Anchore Enterprise](<https://devfeed.tech/articles/introducing-our-newest-ecosystem-integration-anchore-enterprise-13119.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-our-newest-ecosystem-integration-anchore-enterprise>)

Published: 2025-09-23T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-partners](<https://devfeed.tech/tags/chainguard-partners.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [integration](<https://devfeed.tech/tags/integration.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard announces a new integration with Anchore Enterprise. The integration combines Chainguard's secure-by-default container images with Anchore's SBOM management, vulnerability scanning, and automated compliance policy enforcement to support continuous software security and compliance.

### Source excerpt

Discover more about Chainguard's new integration with Anchore Enterprise.

## Introducing Scanfrog: Dodge Container Vulnerabilities

DevFeed: [Introducing Scanfrog: Dodge Container Vulnerabilities](<https://devfeed.tech/articles/introducing-scanfrog-dodge-container-vulnerabilities-13120.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-scanfrog-dodge-container-vulnerabilities>)

Published: 2025-07-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>), [arcade](<https://devfeed.tech/topics/arcade.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-image-vulnerabilities](<https://devfeed.tech/tags/container-image-vulnerabilities.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [free](<https://devfeed.tech/tags/free.md>), [games](<https://devfeed.tech/tags/games.md>), [grype](<https://devfeed.tech/tags/grype.md>), [management](<https://devfeed.tech/tags/management.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [scanfrog](<https://devfeed.tech/tags/scanfrog.md>), [security](<https://devfeed.tech/tags/security.md>), [terminal](<https://devfeed.tech/tags/terminal.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Scanfrog is a Frogger-style terminal game that turns vulnerabilities found in a container image into game obstacles. It uses Grype, a free and open-source vulnerability scanner, to create levels based on vulnerability-scanning results and illustrates why reducing vulnerabilities improves software security.

### Source excerpt

Scanfrog is a Frogger-style game created by one of Chainguard's engineers to showcase how difficult it can be to dodge vulnerabilities in containers.

## Grype Adds OpenVEX Support for Vulnerability Analysis

DevFeed: [Grype Adds OpenVEX Support for Vulnerability Analysis](<https://devfeed.tech/articles/vexed-then-grype-about-it-chainguard-and-anchore-announce-grype-supports-openvex-13311.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/vexed-then-grype-about-it-chainguard-and-anchore-announce-grype-supports-openvex>)

Published: 2023-10-10T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [grype](<https://devfeed.tech/topics/grype.md>), [openvex](<https://devfeed.tech/topics/openvex.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity-and-infrastructure-security-agency](<https://devfeed.tech/tags/cybersecurity-and-infrastructure-security-agency.md>), [grype](<https://devfeed.tech/tags/grype.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

Grype, Anchore's open-source vulnerability scanner, now supports OpenVEX, a machine-readable standard for vulnerability analysis. The article explains how this can provide context for vulnerabilities and help reduce false positives and vulnerability-management effort.

### Source excerpt

Open source vulnerability scanner Grype has added support for OpenVEX, making software supply chain security easier. Learn how to implement it today.

## Chainguard to accelerate VEX adoption through OpenVEX specification

DevFeed: [Chainguard to accelerate VEX adoption through OpenVEX specification](<https://devfeed.tech/articles/chainguard-to-accelerate-vex-adoption-through-openvex-specification-12985.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-to-accelerate-vex-adoption-through-openvex-specification>)

Published: 2023-01-31T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [openvex](<https://devfeed.tech/topics/openvex.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [google](<https://devfeed.tech/tags/google.md>), [images](<https://devfeed.tech/tags/images.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom-vex](<https://devfeed.tech/tags/sbom-vex.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-tool](<https://devfeed.tech/tags/vulnerability-tool.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces the OpenVEX specification and reference toolchain, developed with industry and CISA VEX Working Group collaboration. OpenVEX helps software producers describe vulnerability exploitability and enables consumers to filter false positives, complementing SBOMs.

### Source excerpt

VEX needs the industry to come together to build formats that integrate into existing practices. OpenVEX enables organizations to put VEX into practice.

## GoReleaser v1 -- one year later

DevFeed: [GoReleaser v1 -- one year later](<https://devfeed.tech/articles/goreleaser-v1-one-year-later-37765.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/goreleaser-v1-1year/>)

Author: Carlos Alexandro Becker

Published: 2022-11-14T00:00:00Z

Content type: article

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [releases](<https://devfeed.tech/topics/releases.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Security](<https://devfeed.tech/topics/security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [openssf](<https://devfeed.tech/topics/openssf.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [github](<https://devfeed.tech/tags/github.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>)

### AI overview

A retrospective on GoReleaser's first year after version 1.0.0, covering its development activity, release cadence, community growth, new features, bug fixes, integrations, and progress on security and supply-chain practices.

### Source excerpt

We launched GoReleaser v1 exactly 1 year ago today!