Syft logo

Syft

Open source · SBOM analysis

Syft catalogues the packages in a container image or a directory and writes them out as a software bill of materials. It is the generation half of Anchore's open-source pair: Syft produces the SBOM, Grype matches it against vulnerability data. Both CycloneDX and SPDX output are supported, which matters when the SBOM has to be handed to a customer or an assessor in a standard format.

Key facts

VendorAnchore
LicenceApache-2.0
Latest releasev1.52.0, 17 Sept 2026
Repository since2020
DoesSBOM generation
ReadsContainer images, Filesystems
FormatsCycloneDX, SPDX
Websitegithub.com/anchore/syft
Sourcegithub.com/anchore/syft

Sources

Checked 21 Sept 2026. Spotted something out of date? Tell us.

Other SBOM analysis tools

Need the product tested as well? See Cyber Resilience Act compliance testing providers.