# General

**URL:** https://anchorecommunity.discourse.group/c/general/4.md

[Latest](https://anchorecommunity.discourse.group/latest.md) · [Categories](https://anchorecommunity.discourse.group/categories.md) · [Tags](https://anchorecommunity.discourse.group/tags.md)

---

## [Welcome to Anchore Community! 👋](https://anchorecommunity.discourse.group/t/welcome-to-anchore-community/5)

<div class="topic-metadata">

**Author:** [@system](https://anchorecommunity.discourse.group/u/system)\
**Replies:** 0\
**Last updated:** [May 28, 2024, 8:50am UTC](https://anchorecommunity.discourse.group/t/welcome-to-anchore-community/5 "2024-05-28T08:50:31Z")

</div>

We are so glad you joined us. :wave: Anchore Community This site is for Syft, Grype and General discussion of our Open Source tools :hammer\_and\_wrench: If you’re looking for Anchore Enterprise customer support, head…

---

## [About the General category](https://anchorecommunity.discourse.group/t/about-the-general-category/3)

<div class="topic-metadata">

**Author:** [@system](https://anchorecommunity.discourse.group/u/system)\
**Replies:** 0

</div>

---

## [Best practices for Syft + Grype container image SBOM and vulnerability scanning workflow](https://anchorecommunity.discourse.group/t/best-practices-for-syft-grype-container-image-sbom-and-vulnerability-scanning-workflow/654)

<div class="topic-metadata">

**Author:** [@danvuong0514](https://anchorecommunity.discourse.group/u/danvuong0514)\
**Replies:** 1\
**Last updated:** [July 6, 2026, 2:23pm UTC](https://anchorecommunity.discourse.group/t/best-practices-for-syft-grype-container-image-sbom-and-vulnerability-scanning-workflow/654 "2026-07-06T14:23:09Z")

</div>

Hi Anchore community, I’m currently using Syft and Grype for private container image security reporting. Workflow: syft \<private-registry\>/\<namespace\>/\<image\>:\<tag\> \\ -o cyclonedx-json \\ --scope squashed \\ \> ima…

---

## [Additional properties in CycloneDX-json Grype output](https://anchorecommunity.discourse.group/t/additional-properties-in-cyclonedx-json-grype-output/652)

<div class="topic-metadata">

**Author:** [@staticnoise](https://anchorecommunity.discourse.group/u/staticnoise)\
**Replies:** 4\
**Last updated:** [June 17, 2026, 6:09pm UTC](https://anchorecommunity.discourse.group/t/additional-properties-in-cyclonedx-json-grype-output/652 "2026-06-17T18:09:03Z")

</div>

Hi folks, currently the json output of Grype includes useful metadata missing from the CycloneDX-json format, namely: is fix available for the package was the match direct or indirect (based on package name or upstrea…

---

## [TU Delft research on the Impact of AI-Generated Security Reports on OSS Maintainers & Security Triage](https://anchorecommunity.discourse.group/t/tu-delft-research-on-the-impact-of-ai-generated-security-reports-on-oss-maintainers-security-triage/620)

<div class="topic-metadata">

**Author:** [@Sudharshan-02](https://anchorecommunity.discourse.group/u/Sudharshan-02)\
**Replies:** 3\
**Last updated:** [May 21, 2026, 4:56pm UTC](https://anchorecommunity.discourse.group/t/tu-delft-research-on-the-impact-of-ai-generated-security-reports-on-oss-maintainers-security-triage/620 "2026-05-21T16:56:12Z")

</div>

Hi everyone, I’m currently pursuing my MSc at TU Delft in TU Delft, Netherlands, where I’m conducting my thesis research on how AI-generated security bug reports are affecting open-source maintainers and security triage…

---

## [Unable to identify from which transitive dependency license is been displaying](https://anchorecommunity.discourse.group/t/unable-to-identify-from-which-transitive-dependency-license-is-been-displaying/619)

<div class="topic-metadata">

**Author:** [@anvitha\_haviligi](https://anchorecommunity.discourse.group/u/anvitha_haviligi)\
**Replies:** 2\
**Last updated:** [May 7, 2026, 8:02pm UTC](https://anchorecommunity.discourse.group/t/unable-to-identify-from-which-transitive-dependency-license-is-been-displaying/619 "2026-05-07T20:02:19Z")

</div>

in the screenshot attached, we see CC-BY-ND-3.0 license for the package gawk, i have tried to search license for which package it has mapped using rpm command and also tdnf info for all the transitive, no where it has…

---

## [Proposal: AGENT.md to improve PR quality](https://anchorecommunity.discourse.group/t/proposal-agent-md-to-improve-pr-quality/618)

<div class="topic-metadata">

**Author:** [@witchcraze](https://anchorecommunity.discourse.group/u/witchcraze)\
**Replies:** 1\
**Last updated:** [May 7, 2026, 8:00pm UTC](https://anchorecommunity.discourse.group/t/proposal-agent-md-to-improve-pr-quality/618 "2026-05-07T20:00:49Z")

</div>

Hi, If AI-assisted PRs that ignore project guidelines start being generated at scale, there’s a concern that maintainer review time could be wasted. One idea is to introduce a simple AGENT.md . Initially, it could stay…

---

## [Error import metadata digest is not in the expected format](https://anchorecommunity.discourse.group/t/error-import-metadata-digest-is-not-in-the-expected-format/617)

<div class="topic-metadata">

**Author:** [@Hari21225](https://anchorecommunity.discourse.group/u/Hari21225)\
**Replies:** 1\
**Last updated:** [April 23, 2026, 3:05pm UTC](https://anchorecommunity.discourse.group/t/error-import-metadata-digest-is-not-in-the-expected-format/617 "2026-04-23T15:05:32Z")

</div>

we have upgraded our grype version from 0.77 to 0.95. Then while running out jenkins job to read our scanned files getting the error as import metadata is not in the expected format and failed to load vulnerability db: i…

---

## [Recommended Workflow for Large-Scale Recurring SBOM Scans with Syft and Grype](https://anchorecommunity.discourse.group/t/recommended-workflow-for-large-scale-recurring-sbom-scans-with-syft-and-grype/603)

<div class="topic-metadata">

**Author:** [@enzofrnt](https://anchorecommunity.discourse.group/u/enzofrnt)\
**Replies:** 1\
**Last updated:** [February 27, 2026, 4:13pm UTC](https://anchorecommunity.discourse.group/t/recommended-workflow-for-large-scale-recurring-sbom-scans-with-syft-and-grype/603 "2026-02-27T16:13:13Z")

</div>

Hello, I’m currently working on an architecture where we generate SBOMs using Syft from a large number of different systems, Docker images, and full operating systems. We may have hundreds of them, and we want to run sc…

---

## [Scanning Snaps for Vulnerabilities](https://anchorecommunity.discourse.group/t/scanning-snaps-for-vulnerabilities/588)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 0\
**Last updated:** [December 12, 2025, 6:40pm UTC](https://anchorecommunity.discourse.group/t/scanning-snaps-for-vulnerabilities/588 "2025-12-12T18:40:22Z")

</div>

Hello, friends! I built something that might be of interest to you, using Syft and Grype. It scans snaps for vulnerabilities. It’s called SnapScope, and you can see it at: It scans any snap package you specify tha…

---

## [November 6 | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/november-6-open-source-gardening-live-stream/585)

<div class="topic-metadata">

**Author:** [@Anchore\_hello](https://anchorecommunity.discourse.group/u/Anchore_hello)\
**Replies:** 0\
**Last updated:** [November 4, 2025, 4:03am UTC](https://anchorecommunity.discourse.group/t/november-6-open-source-gardening-live-stream/585 "2025-11-04T04:03:15Z")

</div>

\*\* :wave: Hello everyone!\*\* We’re back with the Anchore Open Source team running a live stream to discuss issues, pull requests, and future roadmap planning in our SBOM and vulnerability tools. :alarm\_clock: Starts at 2…

---

## [October 23rd 2025 | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/october-23rd-2025-open-source-gardening-live-stream/582)

<div class="topic-metadata">

**Author:** [@nurmi](https://anchorecommunity.discourse.group/u/nurmi)\
**Replies:** 0\
**Last updated:** [October 31, 2025, 12:07am UTC](https://anchorecommunity.discourse.group/t/october-23rd-2025-open-source-gardening-live-stream/582 "2025-10-31T00:07:28Z")

</div>

Hello, Anchore community! Here’s a summary of our Open Source Gardening session from October 23, 2025. This week, Will, Keith, Chris, and Alex gathered to discuss a major update to the Grype database, a nuanced bug fix …

---

## [October 16th 2025 | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/october-16th-2025-open-source-gardening-live-stream/581)

<div class="topic-metadata">

**Author:** [@nurmi](https://anchorecommunity.discourse.group/u/nurmi)\
**Replies:** 0\
**Last updated:** [October 30, 2025, 11:53pm UTC](https://anchorecommunity.discourse.group/t/october-16th-2025-open-source-gardening-live-stream/581 "2025-10-30T23:53:43Z")

</div>

Hello, Anchore community! Here’s a summary of our recent Open Source Gardening session from October 16, 2025. The team (Dan, Will, Chris, Keith, and Alex) gathered to discuss several key issues and pull requests from th…

---

## [October 9th 2025 | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/october-9th-2025-open-source-gardening-live-stream/580)

<div class="topic-metadata">

**Author:** [@nurmi](https://anchorecommunity.discourse.group/u/nurmi)\
**Replies:** 0\
**Last updated:** [October 30, 2025, 11:44pm UTC](https://anchorecommunity.discourse.group/t/october-9th-2025-open-source-gardening-live-stream/580 "2025-10-30T23:44:46Z")

</div>

Hello, Anchore community! Here’s a summary of our recent Open Source Gardening session from October 9, 2025. The team (Dan, Alex, Will, Chris, and Keith) went through several community-raised issues and pull requests fo…

---

## [October 30 | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/october-30-open-source-gardening-live-stream/579)

<div class="topic-metadata">

**Author:** [@Anchore\_hello](https://anchorecommunity.discourse.group/u/Anchore_hello)\
**Replies:** 0\
**Last updated:** [October 28, 2025, 3:13am UTC](https://anchorecommunity.discourse.group/t/october-30-open-source-gardening-live-stream/579 "2025-10-28T03:13:06Z")

</div>

\*\* :wave: Hello everyone!\*\* We’re back with the Anchore Open Source team running a live stream to discuss issues, pull requests, and future roadmap planning in our SBOM and vulnerability tools. :alarm\_clock: Starts at 2…

---

## [October 23 | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/october-23-open-source-gardening-live-stream/577)

<div class="topic-metadata">

**Author:** [@Anchore\_hello](https://anchorecommunity.discourse.group/u/Anchore_hello)\
**Replies:** 0\
**Last updated:** [October 19, 2025, 10:48pm UTC](https://anchorecommunity.discourse.group/t/october-23-open-source-gardening-live-stream/577 "2025-10-19T22:48:54Z")

</div>

\*\* :wave: Hello everyone!\*\* We’re back with the Anchore Open Source team running a live stream to discuss issues, pull requests, and future roadmap planning in our SBOM and vulnerability tools. :alarm\_clock: Starts at 2…

---

## [October 9th | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/october-9th-open-source-gardening-live-stream/574)

<div class="topic-metadata">

**Author:** [@Anchore\_hello](https://anchorecommunity.discourse.group/u/Anchore_hello)\
**Replies:** 0\
**Last updated:** [October 7, 2025, 6:31pm UTC](https://anchorecommunity.discourse.group/t/october-9th-open-source-gardening-live-stream/574 "2025-10-07T18:31:21Z")

</div>

\*\* :wave: Hello everyone!\*\* We’re back with the Anchore Open Source team running a live stream to discuss issues, pull requests, and future roadmap planning in our SBOM and vulnerability tools. :alarm\_clock: Starts at 2…

---

## [October 2nd | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/october-2nd-open-source-gardening-live-stream/572)

<div class="topic-metadata">

**Author:** [@Anchore\_hello](https://anchorecommunity.discourse.group/u/Anchore_hello)\
**Replies:** 0\
**Last updated:** [October 2, 2025, 3:59am UTC](https://anchorecommunity.discourse.group/t/october-2nd-open-source-gardening-live-stream/572 "2025-10-02T03:59:34Z")

</div>

\# :wave: Hello everyone! We’re back with the Anchore Open Source team running a live stream to discuss issues, pull requests, and future roadmap planning in our SBOM and vulnerability tools. :alarm\_clock: Starts at 202…

---

## [September 25th | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/september-25th-open-source-gardening-live-stream/569)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 1\
**Last updated:** [September 26, 2025, 11:46am UTC](https://anchorecommunity.discourse.group/t/september-25th-open-source-gardening-live-stream/569 "2025-09-26T11:46:09Z")

</div>

September 25th | Open Source Gardening | Live Stream :wave: Hello everyone! We’re back with the Anchore Open Source team running a live stream to discuss issues, pull requests, and future roadmap planning in our SBOM an…

---

## [Anchore Open Source Weekly Report, Week 38, 2025](https://anchorecommunity.discourse.group/t/anchore-open-source-weekly-report-week-38-2025/568)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 0\
**Last updated:** [September 22, 2025, 2:11pm UTC](https://anchorecommunity.discourse.group/t/anchore-open-source-weekly-report-week-38-2025/568 "2025-09-22T14:11:41Z")

</div>

Anchore Open Source Weekly Report This report covers the community activity in Anchore Open Source Projects from September 14, 2025 to September 20, 2025. Executive Summary The Anchore Open Source team had a productive …

---

## [September 18th | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/september-18th-open-source-gardening-live-stream/561)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 1\
**Last updated:** [September 20, 2025, 3:03pm UTC](https://anchorecommunity.discourse.group/t/september-18th-open-source-gardening-live-stream/561 "2025-09-20T15:03:49Z")

</div>

September 18th | Open Source Gardening | Live Stream :wave: Hello everyone! We’re back with the Anchore Open Source team running a live stream to discuss issues, pull requests, and future roadmap planning in our SBOM an…

---

## [How to map transitive dependencies to parent package?](https://anchorecommunity.discourse.group/t/how-to-map-transitive-dependencies-to-parent-package/565)

<div class="topic-metadata">

**Author:** [@anvitha\_haviligi](https://anchorecommunity.discourse.group/u/anvitha_haviligi)\
**Replies:** 6\
**Last updated:** [September 17, 2025, 2:30pm UTC](https://anchorecommunity.discourse.group/t/how-to-map-transitive-dependencies-to-parent-package/565 "2025-09-17T14:30:33Z")

</div>

We are using syft +dependency tracker for managing SBOMs for different images, when we get some license issues for all transitive dependencies it will be seen as per policy which we have defined, is it possible to displa…

---

## [Why SBOM contains configuration files?](https://anchorecommunity.discourse.group/t/why-sbom-contains-configuration-files/559)

<div class="topic-metadata">

**Author:** [@anvitha\_haviligi](https://anchorecommunity.discourse.group/u/anvitha_haviligi)\
**Replies:** 5\
**Last updated:** [September 17, 2025, 5:41am UTC](https://anchorecommunity.discourse.group/t/why-sbom-contains-configuration-files/559 "2025-09-17T05:41:44Z")

</div>

Hi All, I have tried generating SBOM with syft 1.32 version, i see it contains even configuration files, SBOM should contain only components and dependencies rite ? Adding screenshot for reference. In earlier versions …

---

## [Anchore Open Source Weekly Report, Week 37, 2025](https://anchorecommunity.discourse.group/t/anchore-open-source-weekly-report-week-37-2025/560)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 0\
**Last updated:** [September 15, 2025, 10:42am UTC](https://anchorecommunity.discourse.group/t/anchore-open-source-weekly-report-week-37-2025/560 "2025-09-15T10:42:21Z")

</div>

Anchore Open Source Weekly Report This report covers the community activity in Anchore Open Source Projects from September 7, 2025 to September 13, 2025. Executive Summary The Anchore Open Source ecosystem had a product…

---

## [September 11th | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/september-11th-open-source-gardening-live-stream/556)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 1\
**Last updated:** [September 14, 2025, 10:47am UTC](https://anchorecommunity.discourse.group/t/september-11th-open-source-gardening-live-stream/556 "2025-09-14T10:47:39Z")

</div>

:wave: Hello everyone! We’re back with the Anchore Open Source team running a live stream to discuss issues, pull requests, and future roadmap planning in our SBOM and vulnerability tools. :alarm\_clock: Starts at 2015-0…

---

## [Anchore Open Source Weekly Report - Week 36, 2025](https://anchorecommunity.discourse.group/t/anchore-open-source-weekly-report-week-36-2025/554)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 0\
**Last updated:** [September 8, 2025, 12:52pm UTC](https://anchorecommunity.discourse.group/t/anchore-open-source-weekly-report-week-36-2025/554 "2025-09-08T12:52:38Z")

</div>

Anchore Open Source Weekly Report This report covers the community activity in Anchore Open Source Projects from September 1, 2025 to September 5, 2025. Executive Summary The Anchore Open Source ecosystem delivered stea…

---

## [Any plans for AIBOM using Syft or Grype](https://anchorecommunity.discourse.group/t/any-plans-for-aibom-using-syft-or-grype/543)

<div class="topic-metadata">

**Author:** [@anvitha\_haviligi](https://anchorecommunity.discourse.group/u/anvitha_haviligi)\
**Replies:** 4\
**Last updated:** [September 2, 2025, 6:57pm UTC](https://anchorecommunity.discourse.group/t/any-plans-for-aibom-using-syft-or-grype/543 "2025-09-02T18:57:39Z")

</div>

Hi Team, Any plans to support generate AIBOM using Syft or Grype Regards, Anvitha

---

## [September 4th | Open Source Gardening | Live Stream](https://anchorecommunity.discourse.group/t/september-4th-open-source-gardening-live-stream/550)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 0\
**Last updated:** [September 1, 2025, 11:30am UTC](https://anchorecommunity.discourse.group/t/september-4th-open-source-gardening-live-stream/550 "2025-09-01T11:30:16Z")

</div>

:wave: Hello everyone! We’re back with the Anchore Open Source team running a live stream to discuss issues, pull requests, and future roadmap planning in our SBOM and vulnerability tools. :alarm\_clock: Starts at 2025-0…

---

## [Anchore Open Source Weekly Report - Week 35, 2025](https://anchorecommunity.discourse.group/t/anchore-open-source-weekly-report-week-35-2025/549)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 0\
**Last updated:** [September 1, 2025, 10:28am UTC](https://anchorecommunity.discourse.group/t/anchore-open-source-weekly-report-week-35-2025/549 "2025-09-01T10:28:34Z")

</div>

Anchore Open Source Weekly Report - Week 35, 2025 This report covers the community activity in Anchore Open Source Projects from August 19, 2025 to August 30, 2025. Community Team Meeting Before we get into the “meat an…

---

## ["we track the complete list in our open source SBOM eBook." - the repo is gone](https://anchorecommunity.discourse.group/t/we-track-the-complete-list-in-our-open-source-sbom-ebook-the-repo-is-gone/547)

<div class="topic-metadata">

**Author:** [@Jakub\_Bochenski](https://anchorecommunity.discourse.group/u/Jakub_Bochenski)\
**Replies:** 1\
**Last updated:** [September 1, 2025, 7:34am UTC](https://anchorecommunity.discourse.group/t/we-track-the-complete-list-in-our-open-source-sbom-ebook-the-repo-is-gone/547 "2025-09-01T07:34:03Z")

</div>

How to Generate an SBOM with Free Open Source Tools | Anchore the linked repo https://github.com/popey/sbom\_ebook is not available @popey

[Next page](https://anchorecommunity.discourse.group/c/general/4.md?page=1)
