OSS Tanbou

generate SBOMs from container images, filesystems, and archives in CycloneDX, SPDX, and other formats

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
9,633
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 2, 2026
On this page

Overview

Syft is a CLI and Go library that catalogs software packages from container images, filesystems, and archives and emits Software Bills of Materials in CycloneDX, SPDX, Syft JSON, and other formats across many operating-system and language ecosystems.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Catalog packages from images, directories, and archives

Syft analyzes Docker/OCI images, local filesystems, and archives and combines operating-system packages with application dependencies into one inventory.

Sources: [1]

Emit and convert CycloneDX, SPDX, Syft JSON, and other SBOM formats

A source can be written to multiple SBOM formats in one run, and existing SBOMs can be converted when downstream tooling requires another representation.

Sources: [1]

Feed vulnerability scanners and signed attestations

Syft output integrates directly with Grype for vulnerability scanning and can participate in signed SBOM attestations based on the in-toto specification.

Sources: [1]

Best fit

Fits CI/CD workflows that need standardized artifact inventories

It is useful for generating an SBOM for release images or source trees and retaining that inventory for audits, artifacts, or later scanner input.

Sources: [1]

Before adoption

An SBOM is detected inventory, not a guarantee of complete software composition

Catalogers infer packages from files and metadata. v1.54.0 still contains fixes for PURLs, Java archives, PHP extensions, lockfiles, and other package-identification cases, so critical components should be cross-checked against build metadata.

Sources: [2]

v1.54.0 includes parser hardening and dependency vulnerability remediation

The release adds protections against malformed inputs and cataloger panics and remediates two known vulnerabilities in Syft dependencies. Keep the generator version pinned and updated.

Sources: [2]

Source builds require Go 1.26.8

The v1.54.0 go.mod declares Go 1.26.8. Most users can consume release binaries; source builds and library integrations should verify the toolchain requirement.

Sources: [3]

Official sources

  1. [1]Syft README(2026-10-03)
  2. [2]Syft v1.54.0 release(2026-10-03)
  3. [3]Syft v1.54.0 go.mod(2026-10-03)
  4. [4]Syft Apache-2.0 license(2026-10-03)
Supplemental curator note

Syft is practical for generating SBOMs from images and source directories in CI. An SBOM is the detected package inventory rather than a vulnerability verdict, so use a scanner such as Grype separately and account for cataloger false positives or omissions.

Try it in 3 steps

  1. 1

    Install the pinned v1.54.0 release

    Pass the release tag to the official installer so CI uses a reproducible Syft version.

    curl -sSfL https://get.anchore.io/syft | sudo sh -s -- -b /usr/local/bin v1.54.0
  2. 2

    Generate a CycloneDX SBOM from an image

    Catalog operating-system and language packages in the image and write CycloneDX JSON.

    syft alpine:latest -o cyclonedx-json=./sbom.cdx.json
  3. 3

    Generate an SPDX SBOM from a source directory

    Catalog a repository directory with the same CLI and cross-check critical packages against build metadata.

    syft ./my-project -o spdx-json=./sbom.spdx.json
Check the official README

Growth

Growth trends · Last 30 days

9,633 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
89
Open PRs
140

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • containers
  • docker
  • go
  • golang
  • static-analysis
  • tool
  • oci
  • sbom
  • spdx
  • cyclonedx
  • hacktoberfest
Stars
9,633
Forks
977
Watchers
74
Open issues
507
Contributors
268
Owner type
Organization
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 2, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?