Skip to main content
📋

Syft

Open-source SBOM generator for containers and filesystems

Security
Syft logo

Syft

Open-source SBOM generator for containers and filesystems

Syft is an open-source software bill of materials (SBOM) generator from Anchore that creates detailed inventories of packages, libraries, and dependencies in container images and filesystems. It generates SBOMs in industry-standard formats (SPDX, CycloneDX) required by US government executive orders and enterprise procurement policies. Syft works alongside Grype for vulnerability scanning—first generate the SBOM with Syft, then scan it with Grype to find CVEs.

Key Features

  • SBOM generation
  • SPDX/CycloneDX output
  • Container image support
  • Filesystem scanning
  • NIST compliance
  • Open source
#sbom#supply-chain#containers#compliance#open-source

Get Started

Visit Syft
🟢
Free
Completely free to use

Quick Info

Category
Security
Pricing
Free

More Security Tools