7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Syft

Open source

CLI tool and Go library that generates a Software Bill of Materials from container images, filesystems and archives.

GitHub stars
9.6k
Last commit
today
Repository age
6 years
Version
v1.54.0
Licence
Apache-2.0
Self-hosted
Yes

About Syft

Syft is a command-line tool and Go library for generating a Software Bill of Materials, or SBOM, from container images and filesystems. An SBOM lists the packages inside a piece of software, which helps teams track dependencies and find vulnerable components. It pairs naturally with a scanner such as Grype for vulnerability detection.

It supports dozens of packaging ecosystems, among them Alpine, Debian, RPM, Go, Python, Java, JavaScript, Ruby, Rust, PHP and .NET, and handles OCI, Docker and Singularity image formats. Output can be written as CycloneDX, SPDX or Syft JSON, and SBOMs can be converted between formats. Signed SBOM attestations can be created using the in-toto specification.

Syft is written in Go and released under the Apache-2.0 license, with development sponsored by Anchore. It installs via Homebrew, Docker, Scoop, Chocolatey, Nix and other routes, and documentation includes a getting started guide, CLI reference, configuration reference and JSON schema. Commercial support is available from Anchore.

Key features

  • SBOMs from images, filesystems and archives
  • Dozens of packaging ecosystems supported
  • CycloneDX, SPDX and Syft JSON output
  • Conversion between SBOM formats
  • Signed attestations with in-toto
  • Works alongside Grype scanning

Good fit for

  • →Producing SBOMs in CI pipelines
  • →Inventorying packages inside container images
Built with
Go
Docker
Tags
sbom
supply-chain
containers
cyclonedx
spdx
security
cli
go

Syft: questions and answers

What is Syft used for?
Syft is a CLI tool and Go library that generates a Software Bill of Materials from container images, filesystems and archives. It is a good fit for producing SBOMs in CI pipelines and inventorying packages inside container images.
Is Syft open source?
Yes. Syft is open source under the Apache-2.0 licence. Its source code is on GitHub at anchore/syft and is written mainly in Go.
Is Syft free?
Yes. Syft is open source, so the software itself is free to use.
What are some alternatives to Syft?
Similar open-source tools in the Security category include Grype, Horusec and Dependency-Track. SaaS products in the same category include AgentScan, Socket and Abnormal Security.
Is Syft actively maintained?
Yes. The most recent commit to Syft was on 2 October 2026, and the latest release is v1.54.0, published on 1 October 2026. The project has 9.6k stars on GitHub.

Open-source alternatives to Syft

See all

SaaS alternatives to Syft

See all