9,658 stars · Apache-2.0 · v1.54.1 (2026-10-06) · Track this in Scout
Lists every package inside a container image or a folder as a standard bill of materials, in SPDX or CycloneDX, and changes nothing.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Syft is a Go command-line tool and library that scans container images and filesystems and produces a software bill of materials. It recognises packages from a long list of ecosystems and can emit the result in the two standard formats, SPDX and CycloneDX, as well as its own.
What it is good for. Anyone who ships a container and would struggle to answer "does this contain the library that was in the news yesterday". It is the half of the job that is purely factual: the inventory, with no judgement attached. Its sibling tool takes that inventory and reports known vulnerabilities, which is why the two are usually used together.
- It reads and never writes, so there is nothing to undo and nothing to break.
- It covers a wide range of ecosystems in one pass and emits both standard formats, so the output goes into other people's tools without conversion.
- Very actively developed: v1.54.1 on 6 October 2026 and code on 9 October 2026, the morning this was checked.
- ⚠ The only install command in the README pipes a script from the internet into a root shell:
curl -sSfL https://get.anchore.io/syft | sudo sh -s -- -b /usr/local/bin. Other channels exist — Homebrew, Docker, Scoop, Chocolatey, Nix — but the README names them without giving the commands. - ⚠ It tells you what is there and nothing about whether it is safe. The list on its own is not a finding; you need a second tool to turn it into one.
- 504 open issues against 126 open pull requests, no memory or disk figures published anywhere, no website set in the repository sidebar, and the Apache-2.0 licence file leaves the copyright holder as the unfilled template
Copyright [yyyy] [name of copyright owner]— Anchore's name appears in it nowhere. Building from source needs Go 1.26.8, read from the module file at the release tag.
anchore/grypeThis tool's sibling: it consumes the inventory and reports known vulnerabilities instead of producing one.
Track this in Scout
aquasecurity/trivyAlso generates bills of materials, as one feature of a much broader scanner covering misconfiguration, secrets, clusters and cloud accounts.
Track this in Scout- CycloneDX/cdxgen
Generates the same kind of inventory from source code and build manifests across many languages, CycloneDX-first and written in Node.js.
Track this in Scout
# list everything inside a public image docker run --rm anchore/syft:latest alpine:latest # or scan a folder on this machine docker run --rm -v "$PWD":/src anchore/syft:latest dir:/src # write a standard SPDX file instead of a table docker run --rm -v "$PWD":/src anchore/syft:latest dir:/src \ -o spdx-json > sbom.spdx.json

