Security and privacy · Edition No. 45 · 9 Oct 2026

anchore/syft

Lists every package inside a container image or a folder as a standard bill of materials, in SPDX or CycloneDX, and changes nothing.

← Security and privacyRead the whole edition →

9,658 stars · Apache-2.0 · v1.54.1 (2026-10-06) · Track this in Scout

Lists every package inside a container image or a folder as a standard bill of materials, in SPDX or CycloneDX, and changes nothing.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Syft is a Go command-line tool and library that scans container images and filesystems and produces a software bill of materials. It recognises packages from a long list of ecosystems and can emit the result in the two standard formats, SPDX and CycloneDX, as well as its own.

What it is good for. Anyone who ships a container and would struggle to answer "does this contain the library that was in the news yesterday". It is the half of the job that is purely factual: the inventory, with no judgement attached. Its sibling tool takes that inventory and reports known vulnerabilities, which is why the two are usually used together.

Stars9,658
LicenceApache-2.0
Latestv1.54.1 (2026-10-06)
Good
  • It reads and never writes, so there is nothing to undo and nothing to break.
  • It covers a wide range of ecosystems in one pass and emits both standard formats, so the output goes into other people's tools without conversion.
  • Very actively developed: v1.54.1 on 6 October 2026 and code on 9 October 2026, the morning this was checked.
Watch for
  • ⚠ The only install command in the README pipes a script from the internet into a root shell: curl -sSfL https://get.anchore.io/syft | sudo sh -s -- -b /usr/local/bin. Other channels exist — Homebrew, Docker, Scoop, Chocolatey, Nix — but the README names them without giving the commands.
  • ⚠ It tells you what is there and nothing about whether it is safe. The list on its own is not a finding; you need a second tool to turn it into one.
  • 504 open issues against 126 open pull requests, no memory or disk figures published anywhere, no website set in the repository sidebar, and the Apache-2.0 licence file leaves the copyright holder as the unfilled template Copyright [yyyy] [name of copyright owner] — Anchore's name appears in it nowhere. Building from source needs Go 1.26.8, read from the module file at the release tag.
Similar repositories
Install
# list everything inside a public image
docker run --rm anchore/syft:latest alpine:latest
# or scan a folder on this machine
docker run --rm -v "$PWD":/src anchore/syft:latest dir:/src
# write a standard SPDX file instead of a table
docker run --rm -v "$PWD":/src anchore/syft:latest dir:/src \
  -o spdx-json > sbom.spdx.json
Screenshots
anchore/syft: GitHub preview cardanchore/syft: Screenshot 1

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.