Categories: Cloud & SaaS

Anchore Demonstrates How to Further Software Supply Chain Security with Signed SBOMs and Security Reports

Anchore, a leader in software supply chain security, introduced a demonstration workflow that shows how software producers can create, sign, and share accurate software bill-of-material (SBOM) and security reports to help further the security of software supply chains. As the United States government implements the Executive Order on Improving the Nation’s Cybersecurity, federal agencies expect to require SBOMs from their software vendors. Commercial enterprises can also benefit from verifiable documents that attest to the contents and security status of the software they use.

The demonstration workflow leverages open source tools Syft, Grype, and Sigstore’s Cosign to create and share signed attestations about the security of software applications delivered in containers.

Sponsored

Recommended AI News: Consilio Has Agreed to Acquire the Adecco Group’s Legal Consulting and eDiscovery Business Units of Special Counsel, including D4 and EQ

The workflow details how software producers can:

  • Use Sigstore’s Cosign to sign a software container image
  • Use Syft to produce a comprehensive SBOM that details the contents of the container image and then use Sigstore to create a signed attestation for its validity
  • Use Grype to produce a vulnerability report for a container image and then use Sigstore to create a signed attestation for its validity
  • Deliver the signed container image, SBOM and vulnerability report to their software customer or user

Software users can then verify the software container image, SBOM, and vulnerability report for an accurate picture of both the contents and security status of the software they are using.

The demonstration workflow was developed in partnership with Sigstore and builds off the complementary capabilities of open source tools, Syft, Grype, and Sigstore’s Cosign.

Recommended AI News: Truepic Raises $26 Million Series B Financing Led by M12 – Microsoft’s Venture Fund to Scale World’s Most Secure Camera Technology

Sponsored

Why Software Supply Chain Security is Important

The need for a secure software supply chain increases in priority and urgency each day due to continued and persistent cyberattacks. The widespread use of DevOps processes to speed cloud-native software development has led to a concurrent rise in the use of software containers. An Anchore survey of 400+ large enterprises showed that 65% of respondents have a significant number of applications running in containers.

Containers make it easy to package software during development, but can bring in multiple open source software (OSS) dependencies as applications move through the DevOps pipeline, creating new security requirements. As a result, 63% of survey respondents plan to increase container use and 60% report improving supply chain security as a top initiative.

Anchore and Sigstore Cosign engineers are working in tandem to educate the open source community and raise industry awareness of software supply chain security and available tools to proactively secure the development pipeline.

Recommended AI News: 5thColumn Rebrands As UncommonX with Launch of BOSS Intelligent Security Platform

[To share your insights with us, please write to admin@websitehost.review]

The post Anchore Demonstrates How to Further Software Supply Chain Security with Signed SBOMs and Security Reports appeared first on WebsiteHost.Review.

Website Host Review

Recent Posts

Emerging Trends in Data Center Talent Density: Optimizing for the Future

Originally posted on Innovorg In the rapidly evolving world of data centers, the concept of…

2 days ago

Evocative Recognized as a Top 100 Company by Data Centre Magazine

Evocative, a global provider of digital infrastructure solutions, is included in the Top 100 Companies…

2 days ago

Datalec Precision Installations Honored as Finalist in 2024 DCS Awards

Voting Closes May 3 for Data Centre Managed Services Vendor of the Year and all…

3 days ago

DC BLOX Expands Myrtle Beach Data Center and Cable Landing Station

As reported by WBTW News13 in Myrtle Beach, SC, DC BLOX, a data center and…

3 days ago

The Power Grid Struggle to Keep Up with the Data Center Boom Fueled by AI – as reported by Wall Street Journal

Video posted by Wall Street Journal The rapid growth of data centers, driven by the…

1 week ago

DLC will not come to the rescue of data center sustainability

A growing number of data center operators and equipment vendors are anticipating the proliferation of…

1 week ago