About Syft
Syft is a command-line tool and Go library for generating a Software Bill of Materials, or SBOM, from container images and filesystems. An SBOM lists the packages inside a piece of software, which helps teams track dependencies and find vulnerable components. It pairs naturally with a scanner such as Grype for vulnerability detection.
It supports dozens of packaging ecosystems, among them Alpine, Debian, RPM, Go, Python, Java, JavaScript, Ruby, Rust, PHP and .NET, and handles OCI, Docker and Singularity image formats. Output can be written as CycloneDX, SPDX or Syft JSON, and SBOMs can be converted between formats. Signed SBOM attestations can be created using the in-toto specification.
Syft is written in Go and released under the Apache-2.0 license, with development sponsored by Anchore. It installs via Homebrew, Docker, Scoop, Chocolatey, Nix and other routes, and documentation includes a getting started guide, CLI reference, configuration reference and JSON schema. Commercial support is available from Anchore.
Key features
- SBOMs from images, filesystems and archives
- Dozens of packaging ecosystems supported
- CycloneDX, SPDX and Syft JSON output
- Conversion between SBOM formats
- Signed attestations with in-toto
- Works alongside Grype scanning
Good fit for
- →Producing SBOMs in CI pipelines
- →Inventorying packages inside container images
- Tags
- sbom
- supply-chain
- containers
- cyclonedx
- spdx
- security
- cli
- go
Syft: questions and answers
- What is Syft used for?
- Syft is a CLI tool and Go library that generates a Software Bill of Materials from container images, filesystems and archives. It is a good fit for producing SBOMs in CI pipelines and inventorying packages inside container images.
- Is Syft open source?
- Yes. Syft is open source under the Apache-2.0 licence. Its source code is on GitHub at anchore/syft and is written mainly in Go.
- Is Syft free?
- Yes. Syft is open source, so the software itself is free to use.
- What are some alternatives to Syft?
- Similar open-source tools in the Security category include Grype, Horusec and Dependency-Track. SaaS products in the same category include AgentScan, Socket and Abnormal Security.
- Is Syft actively maintained?
- Yes. The most recent commit to Syft was on 2 October 2026, and the latest release is v1.54.0, published on 1 October 2026. The project has 9.6k stars on GitHub.
Open-source alternatives to Syft
See all
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
Dependency-Track
Security
Dependency-Track is an intelligent Component Analysis platform that allows organizations t
Apache-2.0vs Snyk★ 4.3k
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
Kubescape
Security
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, an
Apache-2.0vs Wiz★ 12k
Lego
Security
Let's Encrypt/ACME client and library written in Go
MITvs DigiCert★ 9.9k
SaaS alternatives to Syft
See all
AgentScan
Security
Scans AI coding agent skills for security issues and distributes reviewed workflows for Claude Code and others
SaaS
Socket
Security
Supply chain security that detects risky open source packages before install
SaaS
Abnormal Security
Security
Behavior-based cloud email security that blocks phishing and account takeover
SaaS
Adverse Monitor
Security
Cyber threat intelligence tool that watches the dark web for incident claims naming your company
SaaS
AgentsAegis
Security
Proxy that injects realistic traps into AI coding assistant workflows to train safer command use
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
