On this page
Overview
Syft is a CLI and Go library that catalogs software packages from container images, filesystems, and archives and emits Software Bills of Materials in CycloneDX, SPDX, Syft JSON, and other formats across many operating-system and language ecosystems.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Catalog packages from images, directories, and archives
Syft analyzes Docker/OCI images, local filesystems, and archives and combines operating-system packages with application dependencies into one inventory.
Sources: [1]
Emit and convert CycloneDX, SPDX, Syft JSON, and other SBOM formats
A source can be written to multiple SBOM formats in one run, and existing SBOMs can be converted when downstream tooling requires another representation.
Sources: [1]
Feed vulnerability scanners and signed attestations
Syft output integrates directly with Grype for vulnerability scanning and can participate in signed SBOM attestations based on the in-toto specification.
Sources: [1]
Best fit
Fits CI/CD workflows that need standardized artifact inventories
It is useful for generating an SBOM for release images or source trees and retaining that inventory for audits, artifacts, or later scanner input.
Sources: [1]
Before adoption
An SBOM is detected inventory, not a guarantee of complete software composition
Catalogers infer packages from files and metadata. v1.54.0 still contains fixes for PURLs, Java archives, PHP extensions, lockfiles, and other package-identification cases, so critical components should be cross-checked against build metadata.
Sources: [2]
v1.54.0 includes parser hardening and dependency vulnerability remediation
The release adds protections against malformed inputs and cataloger panics and remediates two known vulnerabilities in Syft dependencies. Keep the generator version pinned and updated.
Sources: [2]
Source builds require Go 1.26.8
The v1.54.0 go.mod declares Go 1.26.8. Most users can consume release binaries; source builds and library integrations should verify the toolchain requirement.
Sources: [3]
Official sources
- [1]Syft README(2026-10-03)
- [2]Syft v1.54.0 release(2026-10-03)
- [3]Syft v1.54.0 go.mod(2026-10-03)
- [4]Syft Apache-2.0 license(2026-10-03)
Supplemental curator note
Syft is practical for generating SBOMs from images and source directories in CI. An SBOM is the detected package inventory rather than a vulnerability verdict, so use a scanner such as Grype separately and account for cataloger false positives or omissions.
Try it in 3 steps
- 1
Install the pinned v1.54.0 release
Pass the release tag to the official installer so CI uses a reproducible Syft version.
curl -sSfL https://get.anchore.io/syft | sudo sh -s -- -b /usr/local/bin v1.54.0 - 2
Generate a CycloneDX SBOM from an image
Catalog operating-system and language packages in the image and write CycloneDX JSON.
syft alpine:latest -o cyclonedx-json=./sbom.cdx.json - 3
Generate an SPDX SBOM from a source directory
Catalog a repository directory with the same CLI and cross-check critical packages against build metadata.
syft ./my-project -o spdx-json=./sbom.spdx.json
Growth
Growth trends · Last 30 days
9,633 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 89
- Open PRs
- 140
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- containers
- docker
- go
- golang
- static-analysis
- tool
- oci
- sbom
- spdx
- cyclonedx
- hacktoberfest
- Stars
- 9,633
- Forks
- 977
- Watchers
- 74
- Open issues
- 507
- Contributors
- 268
- Owner type
- Organization
- Primary language
- Go
- License
- Apache-2.0
- Repository last updated
- Oct 2, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- legmacs42 Stars
2 shared tag(s) · 1 shared category(s)
Extend a small terminal editor with the same let-go Lisp and public APIs used by its built-in commands
Clojure - Moby72,143 Stars
2 shared tag(s) · Same language
the upstream project for assembling container engines and container-based systems
Go - LocalAI49,374 Stars
2 shared tag(s) · Same language
bring text, image, audio, and video runtimes into one control plane
Go - CasaOS37,267 Stars
2 shared tag(s) · Same language
manage Docker apps, files, and storage on a Linux home server through a personal-cloud UI
Go - Grype12,968 Stars
6 shared tag(s) · 3 shared category(s) · Same language
scan container images, filesystems, and SBOMs against vulnerability data and prioritize findings with EPSS, KEV, and VEX
Go - Trivy38,205 Stars
4 shared tag(s) · 1 shared category(s) · Same language
Scan images, filesystems, repositories, VMs, and Kubernetes for CVEs, secrets, IaC issues, and licenses
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.