Syft
Open source · SBOM analysis
Syft catalogues the packages in a container image or a directory and writes them out as a software bill of materials. It is the generation half of Anchore's open-source pair: Syft produces the SBOM, Grype matches it against vulnerability data. Both CycloneDX and SPDX output are supported, which matters when the SBOM has to be handed to a customer or an assessor in a standard format.
Key facts
| Vendor | Anchore |
|---|---|
| Licence | Apache-2.0 |
| Latest release | v1.52.0, 17 Sept 2026 |
| Repository since | 2020 |
| Does | SBOM generation |
| Reads | Container images, Filesystems |
| Formats | CycloneDX, SPDX |
| Website | github.com/anchore/syft |
| Source | github.com/anchore/syft |
Sources
Checked 21 Sept 2026. Spotted something out of date? Tell us.
Other SBOM analysis tools
Need the product tested as well? See Cyber Resilience Act compliance testing providers.