CIO Influence
CIO Influence News Digital Transformation IT and DevOps

Anchore Vulnerability Scanning Tools Integrated With GitLab 14

Anchore Vulnerability Scanning Tools Integrated With GitLab 14

New Integration of Open Source Tool Grype With GitLab 14 Provides Deep Container Inspection to Aid in Securing the Software Supply Chain

Anchore announced that its open source Grype vulnerability scanner tool is now available in GitLab 14’s container scanning feature. Grype, leveraging Syft libraries, performs a deep inspection of container image contents to create an accurate software bill-of-materials (SBOM) and then produces high-fidelity vulnerability data that can be used to harden the software. This data can be used natively within GitLab workflows and interfaces.

Recommended ITech News: BOTS Inc. JV Partners – Cyber Security Group LLC, Launches Cybhub-Online Marketplace for Curated IT Solutions

The focus of the GitLab 14 release is to deliver a modern DevOps platform with increased velocity, trust and visibility. The integration of Grype enables security-minded engineers and developers to investigate and remediate vulnerability findings with analysis of the software package.

“We are excited to embed these robust container scanning features of Grype within GitLab’s complete DevOps platform. Our built-in security enables DevOps velocity with confidence and these added features from Anchore bring even greater security for cloud native applications,” said Sam White, Senior Product Manager at GitLab.

Recommended ITech News: Kingsoft Cloud Announces Major Strategic Move in Enterprise Cloud Services

“Grype was selected for this integration based on its ease of use and accuracy of results. This is especially important as we see increased demand from software developers and engineers to protect against rising software supply chain attacks by embedding security early in the development process,” said Neil Levine, Vice President of Product at Anchore. “Organizations who want to gain end-to-end visibility and control over container security can use Grype and Syft in conjunction with Anchore Enterprise.”

Grype provides the transparency and detail necessary to investigate why the image vulnerability is being reported. As part of the integration with GitLab 14, users gain valuable information about the vulnerabilities discovered in order to empower users to triage and remediate them with available patches.

Recommended ITech News: The Apache Software Foundation Announces Apache Pinot as a Top-Level Project

Related posts

Cybersecurity Burnout: The Critical Risk for Organizations to Address in 2022, ThreatConnect Research

CIO Influence News Desk

Accenture and Microsoft Strengthen Partnership to Responsible Adoption of Generative AI

Business Wire

Cognitus and Revelation Software Concepts Announce Strategic Partnership

Leave a Comment