Anchore Enterprise by Anchore automates container vulnerability scanning and delivers vulnerability scanning for container images with fewer false positives and faster remediation. It integrates with DevOps tools and generates SBOMs. Anchore Enterprise provides a centralized point with logging and metrics for comprehensive container security. It is a solution for organizations with DevSecOps or compliance programs for software in containers. Anchore Enterprise scans container images, generates SBOMs, identifies vulnerabilities and security problems, and enables prioritization and remediation of issues. It automates vulnerability scanning and monitoring for containerized software in CI/CD pipelines, registries, and Kubernetes platforms. Anchore Enterprise identifies malware, secrets, and security risks, and integrates with DevOps tools through 100% API coverage and fully-documented APIs. It automates scanning in source code repositories, CI/CD pipelines, or container registries. Anchore Enterprise uses Syft and Grype to track SBOMs and vulnerabilities, apply compliance rules, manage false positives, and automate remediation workflows. It pulls vulnerability data from various sources including Alpine Linux SecDB, Amazon Linux ALAS, RedHat RHSAs, and Debian Linux CVE Tracker. Anchore Enterprise scans container images to identify all components in the file system, including the OS, open source packages, and associated metadata. It can examine file contents for malware or exposed secrets and can analyze archive files to find deeply nested components. Anchore Enterprise includes a “Hints” feature that lets developers describe content in their applications for better vulnerability matching and a Corrections feature that allows security teams to correct misidentified metadata to avoid false positives. Anchore Enterprise provides a feed of data with a list of ambiguous or incorrect vulnerability data to prevent false positives across deployments.