Syft is a free, open-source tool from Anchore that generates SBOMs from container images and filesystems in CycloneDX, SPDX, and Syft JSON formats.
Category
Security
Pricing
Free
Verified
Not yet
Last updated
July 17, 2026
Free Plan
What is Syft?
Syft is an open-source CLI tool and Go library, sponsored by Anchore, that generates Software Bills of Materials from container images and filesystems. It supports dozens of package ecosystems, including Alpine, Debian, RPM, Go, Python, Java, JavaScript, Ruby, Rust, PHP, and .NET.
Syft outputs SBOMs in industry-standard formats such as CycloneDX and SPDX, as well as its own Syft JSON format, and can create signed SBOM attestations using the in-toto specification. It is released under the Apache-2.0 license and written in Go.
Who Syft is for
Syft is for developers and security teams who need to catalog software dependencies in containerized applications and projects, typically as a precursor to vulnerability scanning with a tool such as Grype.
Key Features
SBOM generation — Creates SBOMs from container images, filesystems, and archives.