# Latest

**URL:** https://anchorecommunity.discourse.group/latest.md

[Latest](https://anchorecommunity.discourse.group/latest.md) · [Categories](https://anchorecommunity.discourse.group/categories.md) · [Tags](https://anchorecommunity.discourse.group/tags.md)

---

## [Welcome to Anchore Community! 👋](https://anchorecommunity.discourse.group/t/welcome-to-anchore-community/5)

<div class="topic-metadata">

**Author:** [@system](https://anchorecommunity.discourse.group/u/system)\
**Replies:** 0\
**Last updated:** [May 28, 2024, 8:50am UTC](https://anchorecommunity.discourse.group/t/welcome-to-anchore-community/5 "2024-05-28T08:50:31Z")

</div>

We are so glad you joined us. :wave: Anchore Community This site is for Syft, Grype and General discussion of our Open Source tools :hammer\_and\_wrench: If you’re looking for Anchore Enterprise customer support, head…

---

## [PSA: Update to the weekly livestream format, and no livestream(s) next week (Sep 24th, 2026)](https://anchorecommunity.discourse.group/t/psa-update-to-the-weekly-livestream-format-and-no-livestream-s-next-week-sep-24th-2026/661)

<div class="topic-metadata">

**Author:** [@nurmi](https://anchorecommunity.discourse.group/u/nurmi)\
**Replies:** 0\
**Last updated:** [September 17, 2026, 8:36pm UTC](https://anchorecommunity.discourse.group/t/psa-update-to-the-weekly-livestream-format-and-no-livestream-s-next-week-sep-24th-2026/661 "2026-09-17T20:36:57Z")

</div>

Hello Anchore Community! Each week, we have a lively discussion about your issues, PRs, questions and hot topics about any/all things Anchore OSS and security/SBOM/compliance engineering in general - not uncommonly, we’…

---

## [Disabling Syft network calls from the CLI](https://anchorecommunity.discourse.group/t/disabling-syft-network-calls-from-the-cli/660)

<div class="topic-metadata">

**Author:** [@Jonas\_Wielage](https://anchorecommunity.discourse.group/u/Jonas_Wielage)\
**Replies:** 0\
**Last updated:** [September 15, 2026, 11:18am UTC](https://anchorecommunity.discourse.group/t/disabling-syft-network-calls-from-the-cli/660 "2026-09-15T11:18:29Z")

</div>

Hi all, I’d like to start a discussion about running syft in a fully offline mode — meaning a configuration where syft is guaranteed not to make any outbound network call. Why I need it My organization places constrai…

---

## [Tracing elements of grype json output](https://anchorecommunity.discourse.group/t/tracing-elements-of-grype-json-output/659)

<div class="topic-metadata">

**Author:** [@anwarani-ext-ks](https://anchorecommunity.discourse.group/u/anwarani-ext-ks)\
**Replies:** 0\
**Last updated:** [August 20, 2026, 3:52am UTC](https://anchorecommunity.discourse.group/t/tracing-elements-of-grype-json-output/659 "2026-08-20T03:52:12Z")

</div>

Howdy, I have a couple of questions regarding grype vuln scan output: How can I trace which provider the matches.vulnerability.description field comes from? Can I set nvd as the first option for the matches.vulnerabil…

---

## [Vulnerability scanner as a service for linux devices using syft](https://anchorecommunity.discourse.group/t/vulnerability-scanner-as-a-service-for-linux-devices-using-syft/658)

<div class="topic-metadata">

**Author:** [@Hriday\_Pradhan](https://anchorecommunity.discourse.group/u/Hriday_Pradhan)\
**Replies:** 0\
**Last updated:** [August 18, 2026, 11:40am UTC](https://anchorecommunity.discourse.group/t/vulnerability-scanner-as-a-service-for-linux-devices-using-syft/658 "2026-08-18T11:40:57Z")

</div>

Hey everyone! I came across Syft while exploring options for a project I’m working on and it seems like it could be a great fit. Would appreciate any guidance or pointers to existing threads! Use case: We’re building a…

---

## [Adding a new matcher](https://anchorecommunity.discourse.group/t/adding-a-new-matcher/656)

<div class="topic-metadata">

**Author:** [@thaines](https://anchorecommunity.discourse.group/u/thaines)\
**Replies:** 0\
**Last updated:** [July 21, 2026, 8:14pm UTC](https://anchorecommunity.discourse.group/t/adding-a-new-matcher/656 "2026-07-21T20:14:35Z")

</div>

spack is a package manager similar to conan or vcpkg that can build software from source covering a wide array of languages, runtimes, compilers, and configurations (it can also use signed packages from its public binary…

---

## [PSA: No livestream(s) next week (July 30th, 2026)](https://anchorecommunity.discourse.group/t/psa-no-livestream-s-next-week-july-30th-2026/655)

<div class="topic-metadata">

**Author:** [@nurmi](https://anchorecommunity.discourse.group/u/nurmi)\
**Replies:** 0\
**Last updated:** [July 16, 2026, 10:44pm UTC](https://anchorecommunity.discourse.group/t/psa-no-livestream-s-next-week-july-30th-2026/655 "2026-07-16T22:44:37Z")

</div>

Hello Anchore Community! We need to cancel an upcoming Anchore OSS Gardening Livestream session (Thursday, July 30th), as we won’t be in a place where the ability to run the live stream is guaranteed. However, we’ve pr…

---

## [Best practices for Syft + Grype container image SBOM and vulnerability scanning workflow](https://anchorecommunity.discourse.group/t/best-practices-for-syft-grype-container-image-sbom-and-vulnerability-scanning-workflow/654)

<div class="topic-metadata">

**Author:** [@danvuong0514](https://anchorecommunity.discourse.group/u/danvuong0514)\
**Replies:** 1\
**Last updated:** [July 6, 2026, 2:23pm UTC](https://anchorecommunity.discourse.group/t/best-practices-for-syft-grype-container-image-sbom-and-vulnerability-scanning-workflow/654 "2026-07-06T14:23:09Z")

</div>

Hi Anchore community, I’m currently using Syft and Grype for private container image security reporting. Workflow: syft \<private-registry\>/\<namespace\>/\<image\>:\<tag\> \\ -o cyclonedx-json \\ --scope squashed \\ \> ima…

---

## [Grype-DB has no new Ubuntu data since 19 June](https://anchorecommunity.discourse.group/t/grype-db-has-no-new-ubuntu-data-since-19-june/653)

<div class="topic-metadata">

**Author:** [@floric](https://anchorecommunity.discourse.group/u/floric)\
**Replies:** 1\
**Last updated:** [June 24, 2026, 11:21am UTC](https://anchorecommunity.discourse.group/t/grype-db-has-no-new-ubuntu-data-since-19-june/653 "2026-06-24T11:21:36Z")

</div>

Hey :slight\_smile: unfortunately the Grype-DB ist outdated since 06/19. Can you check it? Kind regards

---

## [Indirect matches (vulnerabilities affecting the upstream packages) are sometimes too broad](https://anchorecommunity.discourse.group/t/indirect-matches-vulnerabilities-affecting-the-upstream-packages-are-sometimes-too-broad/523)

<div class="topic-metadata">

**Author:** [@staticnoise](https://anchorecommunity.discourse.group/u/staticnoise)\
**Replies:** 11\
**Last updated:** [June 18, 2026, 1:41pm UTC](https://anchorecommunity.discourse.group/t/indirect-matches-vulnerabilities-affecting-the-upstream-packages-are-sometimes-too-broad/523 "2026-06-18T13:41:28Z")

</div>

Hello, I want to ask about upstream matches in Grype. Currently Grype results seem to include all vulnerabilities affecting the upstream package. For example, python-perf package with upstream of kernel includes all v…

---

## [Additional properties in CycloneDX-json Grype output](https://anchorecommunity.discourse.group/t/additional-properties-in-cyclonedx-json-grype-output/652)

<div class="topic-metadata">

**Author:** [@staticnoise](https://anchorecommunity.discourse.group/u/staticnoise)\
**Replies:** 4\
**Last updated:** [June 17, 2026, 6:09pm UTC](https://anchorecommunity.discourse.group/t/additional-properties-in-cyclonedx-json-grype-output/652 "2026-06-17T18:09:03Z")

</div>

Hi folks, currently the json output of Grype includes useful metadata missing from the CycloneDX-json format, namely: is fix available for the package was the match direct or indirect (based on package name or upstrea…

---

## [PSA: No livestream(s) next week (June 11, 2026)](https://anchorecommunity.discourse.group/t/psa-no-livestream-s-next-week-june-11-2026/649)

<div class="topic-metadata">

**Author:** [@nurmi](https://anchorecommunity.discourse.group/u/nurmi)\
**Replies:** 0\
**Last updated:** [June 5, 2026, 6:21pm UTC](https://anchorecommunity.discourse.group/t/psa-no-livestream-s-next-week-june-11-2026/649 "2026-06-05T18:21:06Z")

</div>

Hello Anchore Community! We unfortunately need to cancel next week’s Anchore OSS Gardening Livestream session (Thursday, June 11th), as the team is getting together for an in-person summit, and most will be travelling d…

---

## [TU Delft research on the Impact of AI-Generated Security Reports on OSS Maintainers & Security Triage](https://anchorecommunity.discourse.group/t/tu-delft-research-on-the-impact-of-ai-generated-security-reports-on-oss-maintainers-security-triage/620)

<div class="topic-metadata">

**Author:** [@Sudharshan-02](https://anchorecommunity.discourse.group/u/Sudharshan-02)\
**Replies:** 3\
**Last updated:** [May 21, 2026, 4:56pm UTC](https://anchorecommunity.discourse.group/t/tu-delft-research-on-the-impact-of-ai-generated-security-reports-on-oss-maintainers-security-triage/620 "2026-05-21T16:56:12Z")

</div>

Hi everyone, I’m currently pursuing my MSc at TU Delft in TU Delft, Netherlands, where I’m conducting my thesis research on how AI-generated security bug reports are affecting open-source maintainers and security triage…

---

## [Unable to identify from which transitive dependency license is been displaying](https://anchorecommunity.discourse.group/t/unable-to-identify-from-which-transitive-dependency-license-is-been-displaying/619)

<div class="topic-metadata">

**Author:** [@anvitha\_haviligi](https://anchorecommunity.discourse.group/u/anvitha_haviligi)\
**Replies:** 2\
**Last updated:** [May 7, 2026, 8:02pm UTC](https://anchorecommunity.discourse.group/t/unable-to-identify-from-which-transitive-dependency-license-is-been-displaying/619 "2026-05-07T20:02:19Z")

</div>

in the screenshot attached, we see CC-BY-ND-3.0 license for the package gawk, i have tried to search license for which package it has mapped using rpm command and also tdnf info for all the transitive, no where it has…

---

## [Proposal: AGENT.md to improve PR quality](https://anchorecommunity.discourse.group/t/proposal-agent-md-to-improve-pr-quality/618)

<div class="topic-metadata">

**Author:** [@witchcraze](https://anchorecommunity.discourse.group/u/witchcraze)\
**Replies:** 1\
**Last updated:** [May 7, 2026, 8:00pm UTC](https://anchorecommunity.discourse.group/t/proposal-agent-md-to-improve-pr-quality/618 "2026-05-07T20:00:49Z")

</div>

Hi, If AI-assisted PRs that ignore project guidelines start being generated at scale, there’s a concern that maintainer review time could be wasted. One idea is to introduce a simple AGENT.md . Initially, it could stay…

---

## [EOL can be developed in grype](https://anchorecommunity.discourse.group/t/eol-can-be-developed-in-grype/420)

<div class="topic-metadata">

**Author:** [@TimBrown1611](https://anchorecommunity.discourse.group/u/TimBrown1611)\
**Replies:** 2\
**Last updated:** [May 1, 2026, 6:42pm UTC](https://anchorecommunity.discourse.group/t/eol-can-be-developed-in-grype/420 "2026-05-01T18:42:08Z")

</div>

Today I saw the API of EOL was upgraded and full information can be extracted from the API. I think it is possible now to add this information to grype. here is the relevant issue - Add capability to detect EOL package…

---

## [Support for PostgreSQL or MariaDB as a backend for the Grype database](https://anchorecommunity.discourse.group/t/support-for-postgresql-or-mariadb-as-a-backend-for-the-grype-database/616)

<div class="topic-metadata">

**Author:** [@enzofrnt](https://anchorecommunity.discourse.group/u/enzofrnt)\
**Replies:** 3\
**Last updated:** [May 1, 2026, 5:21pm UTC](https://anchorecommunity.discourse.group/t/support-for-postgresql-or-mariadb-as-a-backend-for-the-grype-database/616 "2026-05-01T17:21:13Z")

</div>

Hello, First of all, thank you for the work you are doing around open-source tools for vulnerability and SBOM management. The Grype database you use is very powerful, but its usage is currently limited to a SQLite data…

---

## [Error import metadata digest is not in the expected format](https://anchorecommunity.discourse.group/t/error-import-metadata-digest-is-not-in-the-expected-format/617)

<div class="topic-metadata">

**Author:** [@Hari21225](https://anchorecommunity.discourse.group/u/Hari21225)\
**Replies:** 1\
**Last updated:** [April 23, 2026, 3:05pm UTC](https://anchorecommunity.discourse.group/t/error-import-metadata-digest-is-not-in-the-expected-format/617 "2026-04-23T15:05:32Z")

</div>

we have upgraded our grype version from 0.77 to 0.95. Then while running out jenkins job to read our scanned files getting the error as import metadata is not in the expected format and failed to load vulnerability db: i…

---

## [Syft is not listing the packages under dev\_dependencies section in package-lock.json](https://anchorecommunity.discourse.group/t/syft-is-not-listing-the-packages-under-dev-dependencies-section-in-package-lock-json/614)

<div class="topic-metadata">

**Author:** [@anvitha\_haviligi](https://anchorecommunity.discourse.group/u/anvitha_haviligi)\
**Replies:** 7\
**Last updated:** [March 25, 2026, 4:22am UTC](https://anchorecommunity.discourse.group/t/syft-is-not-listing-the-packages-under-dev-dependencies-section-in-package-lock-json/614 "2026-03-25T04:22:10Z")

</div>

We scanned nodejs git repository which has both package.json and package-lock.json, we observed packages under devdependencies are not listed in sbom. Please help us in resolving the issue. Regards, Anvitha

---

## [PSA: No livestream(s) next week (Mar 26th, 2026)](https://anchorecommunity.discourse.group/t/psa-no-livestream-s-next-week-mar-26th-2026/615)

<div class="topic-metadata">

**Author:** [@nurmi](https://anchorecommunity.discourse.group/u/nurmi)\
**Replies:** 0\
**Last updated:** [March 21, 2026, 12:58am UTC](https://anchorecommunity.discourse.group/t/psa-no-livestream-s-next-week-mar-26th-2026/615 "2026-03-21T00:58:50Z")

</div>

Hello Anchore Community! We unfortunately need to cancel next week’s Anchore OSS Gardening Livestream session (Thursday, March 26th), as we won’t be in a place where the ability to run the live stream is guaranteed. Ho…

---

## [Grype DB schema v5 will be EOL on March 6, 2026](https://anchorecommunity.discourse.group/t/grype-db-schema-v5-will-be-eol-on-march-6-2026/591)

<div class="topic-metadata">

**Author:** [@willmurphy](https://anchorecommunity.discourse.group/u/willmurphy)\
**Replies:** 1\
**Last updated:** [March 9, 2026, 8:33pm UTC](https://anchorecommunity.discourse.group/t/grype-db-schema-v5-will-be-eol-on-march-6-2026/591 "2026-03-09T20:33:28Z")

</div>

Hi all, Last March, we released Grype v0.88.0, which is the first Grype to use the Grype DB schema v6. Right now our policy is to support the old schema for a year after the new one comes out. So on March 6, 2026, we wi…

---

## [Missing package identification from .zap packaging](https://anchorecommunity.discourse.group/t/missing-package-identification-from-zap-packaging/599)

<div class="topic-metadata">

**Author:** [@santhosh](https://anchorecommunity.discourse.group/u/santhosh)\
**Replies:** 3\
**Last updated:** [March 6, 2026, 2:33am UTC](https://anchorecommunity.discourse.group/t/missing-package-identification-from-zap-packaging/599 "2026-03-06T02:33:14Z")

</div>

We have observed that some third party vendor softwares are using .zap packaging type for Java packages. Syft can’t parse or read package information from .zap type. Example, https://github.com/zaproxy/zaproxy/releases…

---

## [PSA: No livestream(s) this week (Mar 5th, 2026)](https://anchorecommunity.discourse.group/t/psa-no-livestream-s-this-week-mar-5th-2026/605)

<div class="topic-metadata">

**Author:** [@nurmi](https://anchorecommunity.discourse.group/u/nurmi)\
**Replies:** 0\
**Last updated:** [March 3, 2026, 11:32pm UTC](https://anchorecommunity.discourse.group/t/psa-no-livestream-s-this-week-mar-5th-2026/605 "2026-03-03T23:32:08Z")

</div>

Hello Anchore Community! We’re cancelling this week’s Anchore OSS Gardening Livestream session, but look forward to resuming our regular weekly schedule next week and beyond!

---

## [Recommended Workflow for Large-Scale Recurring SBOM Scans with Syft and Grype](https://anchorecommunity.discourse.group/t/recommended-workflow-for-large-scale-recurring-sbom-scans-with-syft-and-grype/603)

<div class="topic-metadata">

**Author:** [@enzofrnt](https://anchorecommunity.discourse.group/u/enzofrnt)\
**Replies:** 1\
**Last updated:** [February 27, 2026, 4:13pm UTC](https://anchorecommunity.discourse.group/t/recommended-workflow-for-large-scale-recurring-sbom-scans-with-syft-and-grype/603 "2026-02-27T16:13:13Z")

</div>

Hello, I’m currently working on an architecture where we generate SBOMs using Syft from a large number of different systems, Docker images, and full operating systems. We may have hundreds of them, and we want to run sc…

---

## [Evaluating Anchore Score Alignment with ISO/SAE 21434 and Automotive Functional Safety Risk](https://anchorecommunity.discourse.group/t/evaluating-anchore-score-alignment-with-iso-sae-21434-and-automotive-functional-safety-risk/598)

<div class="topic-metadata">

**Author:** [@Devashri\_Datta](https://anchorecommunity.discourse.group/u/Devashri_Datta)\
**Replies:** 3\
**Last updated:** [February 6, 2026, 7:00pm UTC](https://anchorecommunity.discourse.group/t/evaluating-anchore-score-alignment-with-iso-sae-21434-and-automotive-functional-safety-risk/598 "2026-02-06T19:00:00Z")

</div>

Dear Anchore Engineering & Community Team, I am evaluating how the Anchore Score—your composite security index comprising CVSS, EPSS, and CISA KEV status—is interpreted within highly regulated software supply chains, sp…

---

## [CVE fallback for other ecosystems](https://anchorecommunity.discourse.group/t/cve-fallback-for-other-ecosystems/597)

<div class="topic-metadata">

**Author:** [@bhogan](https://anchorecommunity.discourse.group/u/bhogan)\
**Replies:** 5\
**Last updated:** [February 4, 2026, 4:03am UTC](https://anchorecommunity.discourse.group/t/cve-fallback-for-other-ecosystems/597 "2026-02-04T04:03:36Z")

</div>

I am curious about CPE fallback matching. The docs linked here list 5 specific package types that rely on CPE matching (binary executables, Homebrew, Jenkins, Conda, WordPress). Is that list exhaustive, or should we ex…

---

## [Grype is reporting a high number of vulnerabilities in one instance, while the other scan returns zero findings.](https://anchorecommunity.discourse.group/t/grype-is-reporting-a-high-number-of-vulnerabilities-in-one-instance-while-the-other-scan-returns-zero-findings/594)

<div class="topic-metadata">

**Author:** [@Phong\_Tr\_n](https://anchorecommunity.discourse.group/u/Phong_Tr_n)\
**Replies:** 2\
**Last updated:** [January 26, 2026, 2:13am UTC](https://anchorecommunity.discourse.group/t/grype-is-reporting-a-high-number-of-vulnerabilities-in-one-instance-while-the-other-scan-returns-zero-findings/594 "2026-01-26T02:13:51Z")

</div>

Dear Anchore, I apologize for the interruption, but I am encountering a technical issue and would greatly appreciate your expert opinion. Our initial image scans were completely clean and remain so to this day. However…

---

## [Help with new provider](https://anchorecommunity.discourse.group/t/help-with-new-provider/596)

<div class="topic-metadata">

**Author:** [@Ildar\_Mulyukov](https://anchorecommunity.discourse.group/u/Ildar_Mulyukov)\
**Replies:** 1\
**Last updated:** [January 23, 2026, 11:35am UTC](https://anchorecommunity.discourse.group/t/help-with-new-provider/596 "2026-01-23T11:35:49Z")

</div>

I’ve made some patches for Vunnel and Grype: Draft: providers: add BellSoft OSV provider by i-bs · Pull Request #924 · anchore/vunnel · GitHub . It builds fine but Grype can’t find the relevant CVE data. Can anyone plea…

---

## [PSA: No livestream(s) this or next week (Dec 25, Jan 1), happy holidays!](https://anchorecommunity.discourse.group/t/psa-no-livestream-s-this-or-next-week-dec-25-jan-1-happy-holidays/590)

<div class="topic-metadata">

**Author:** [@nurmi](https://anchorecommunity.discourse.group/u/nurmi)\
**Replies:** 0\
**Last updated:** [December 22, 2025, 7:04pm UTC](https://anchorecommunity.discourse.group/t/psa-no-livestream-s-this-or-next-week-dec-25-jan-1-happy-holidays/590 "2025-12-22T19:04:34Z")

</div>

Hello Anchore Community, Happy Holidays and prem-emptive Happy New Year! We’re cancelling next week’s Open Source Gardening | Live Stream due to both landing on holidays (Dec 25th, Jan 1st) - we’ll see you all in 2026!

---

## [The OSS tools have a new documentation site!](https://anchorecommunity.discourse.group/t/the-oss-tools-have-a-new-documentation-site/589)

<div class="topic-metadata">

**Author:** [@wagoodman](https://anchorecommunity.discourse.group/u/wagoodman)\
**Replies:** 0\
**Last updated:** [December 17, 2025, 3:48pm UTC](https://anchorecommunity.discourse.group/t/the-oss-tools-have-a-new-documentation-site/589 "2025-12-17T15:48:26Z")

</div>

Our OSS tools have a shiny new docs site! oss.anchore.com There you’ll find user guides, detailed references, architecture docs, guides for contributors who want to jump in, and more. The site itself is open source too…

[Next page](https://anchorecommunity.discourse.group/latest.md?page=1)
