awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
SongStitch avatar

SongStitch/anchor

0
View on GitHub↗
24 stars·0 forks·Go·GPL-2.0·14 views

Anchor

A tool for anchoring dependencies in dockerfiles

Features

  • Image Scanning and SBOM - Pins dependencies to ensure reproducible builds.

Star history

Star history chart for songstitch/anchorStar history chart for songstitch/anchor

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Anchor

These projects share indexed features with Anchor. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • anchore/syftanchore avatar

    anchore/syft

    8,399View on GitHub↗

    Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes container images and filesystems to produce comprehensive inventories of installed packages and dependencies in standard formats. Additionally, it serves as a software attestation tool and an SBOM format converter. The project distinguishes itself through the ability to create cryptographically signed attestations for software inventories to ensure provenance and integrity. It also provides the capability to transform software bills of materials between different industry sche

    Gocontainerscyclonedxdocker
    View on GitHub↗8,399
  • aquasecurity/trivyaquasecurity avatar

    aquasecurity/trivy

    36,462View on GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    View on GitHub↗36,462
  • deadnews/pindockdeadnews avatar

    deadnews/pindock

    2View on GitHub↗

    Pin and update Docker image digests in Dockerfiles and compose files

    Go
    View on GitHub↗2
  • anchore/grypeanchore avatar

    anchore/grype

    12,423View on GitHub↗

    Grype is a command-line security scanner designed to identify known vulnerabilities within container images, filesystems, and software manifests. It functions as a software composition analysis tool that detects security flaws in application components and open-source libraries to support supply chain security. The tool distinguishes itself by reconstructing the final state of container images through layered filesystem inspection and normalizing diverse package formats into a unified dependency graph. It maintains a local cache of security advisories synchronized from multiple upstream sourc

    Gocontainer-imagecontainerscyclonedx
    View on GitHub↗12,423
Compare all 11 related projects→

Frequently asked questions

What does songstitch/anchor do?

A tool for anchoring dependencies in dockerfiles

What are the main features of songstitch/anchor?

The main features of songstitch/anchor are: Image Scanning and SBOM.

Which projects share features with songstitch/anchor?

Projects with overlapping indexed features include: anchore/grype — Grype is a command-line security scanner designed to identify known vulnerabilities within container images,… anchore/syft — Syft is a software bill of materials generator, container image scanner, and software dependency catalog. It analyzes… aquasecurity/trivy — Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container… deadnews/pindock — Pin and update Docker image digests in Dockerfiles and compose files. docker/scout-cli — Docker Scout CLI. in-toto/in-toto — in-toto is a framework to protect supply chain integrity.