Home / Syft

Open source SBOM generator

Syft by Anchore

An open source tool for generating a Software Bill of Materials (SBOM) from container images and filesystems.

Use Syft, a CLI tool and Go library, to generate SBOMs for container images, source code projects, filesystems, and archives. Build efficient and exceptional vulnerability scanning pipelines by providing Syft generated SBOMs directly to vulnerability scanners like Grype.


Catalogs your software down to the file level

Syft deeply inspects anything you throw at it – container images, source code projects, local directories, archives and more – to build a comprehensive inventory of your software. By analyzing your software down to the file level, it catalogs every component to ensure complete visibility into the applications and libraries present in your environment.


Generates standardized SBOMs in your CI/CD pipeline

Integrate Syft directly into your build pipelines to ensure that every build produces a standardized SBOM without slowing down release cycles. This automated pipeline integration enables continuous compliance, seamless artifact signing, and simplified vulnerability tracking.

  • Integrations: Deploy using the GitHub Action or use the Syft CLI for seamless integration into your CI platform of choice (Jenkins, Gitlab, and more).
  • Supported Formats: Output standardized SBOMs in formats including SPDX, CycloneDX, or Syft JSON.

Discovers direct and transitive dependencies

Modern application source code projects declare a set of direct dependencies, but by the time they are prepared for deployment the final build contains a lot more transitive and supporting dependencies. Syft’s “if it’s there, we’ll tell you about it” approach to software analysis ensures that your SBOM will contain a comprehensive list of Java, Python, Go, NPM, and other software artifacts that have been discovered, and how they relate to each other and your application.


Used by Grype for vulnerability scanning

Syft and Grype are designed to work together for more efficient, ongoing vulnerability scanning. Syft first generates an SBOM, creating a complete inventory of all packages in containers, source code project directories, and filesystems.

With an SBOM that represents a static set of software, Grype can then perform its entire security scanning pass without the need to re-analyze the original material, using only the SBOM as input. This “scan once, reuse many times” approach not only speeds up scans in CI/CD pipelines but also enables continuous re-evaluation of risk as vulnerability data changes without the need to perform the expensive operation of re-scanning the original software material.

Learn more about Grype >


Secure Containers with Anchore Enterprise

Anchore Enterprise builds on Syft’s open source SBOM tool for continuous container security, driving increased scalability and productivity, policy-based compliance, and role-based reporting for business units and security teams.

See how NVIDIA secured containers with Anchore Enterprise. 

Integrations

Syft Frequently Asked Questions (FAQs)

Chevron icon What is a Syft scan?

A Syft scan is the process of generating an SBOM by cataloging all software packages, dependencies, and components contained within a container image, filesystem, or other software artifact.

Chevron icon Who is Syft best for?

Syft is best for developers, DevOps teams, security engineers, and platform teams that need a fast, open source way to generate Software Bills of Materials. It is especially useful for teams that want to add SBOM generation to local development workflows, CI/CD pipelines, vulnerability scanning processes, or software supply chain security programs.

For organizations that need to manage SBOMs at enterprise scale, connect SBOM generation to policy enforcement, or support broader compliance and governance workflows, Anchore Enterprise builds on Syft’s capabilities to support SBOM management, policy enforcement, and software supply chain security at scale.

Chevron icon What is the difference between Grype and Syft?

Grype and Syft are two of Anchore’s open source tools, alongside Grant. While they can be used in tandem for a more complete software supply chain security workflow, each serves a distinct purpose and can be run independently. Syft generates comprehensive software bills of materials (SBOMs). Grype is a vulnerability scanner that identifies and prioritizes known vulnerabilities from an SBOM, container image, or project directory. Grant is a license compliance tool that checks licenses in container images, SBOMs, and filesystems.

Chevron icon How do I generate an SBOM with Syft?

Generating an SBOM with Syft is simple. It can be done in just a few steps:

  1. Install Syft
  2. Validate the installation
  3. Generate an SBOM with a simple command
  4. Choose an SBOM format
  5. Optional: Use additional Syft features to output the file, create signed SBOM attestations, and more.

For full step-by-step instructions and examples, check out our full guide to SBOM generation.

Chevron icon What packaging ecosystems does Syft support?

Syft supports dozens of packaging ecosystems, such as Alpine (apk), Debian (dpkg), RPM, Go, Python, Java, JavaScript, Ruby, Rust, PHP, .NET, and many more. See the full list here: https://oss.anchore.com/docs/capabilities/all-packages/

Chevron icon What output formats does Syft support?

Syft supports multiple output formats, including CycloneDX, SPDX, Syft JSON, and more (see the full list here: https://oss.anchore.com/docs/guides/sbom/formats/).  It also includes the ability to convert between SBOM formats

Chevron icon How does Syft compare to other SBOM generation tools?

Syft is one of the most popular open source SBOM generators. Compared to other open source tools like Trivy, cdxgen, and Microsoft’s SBOM Tool, Syft stands out for its broad ecosystem support, flexible output formats, and ability to generate SBOMs from container images, filesystems, source code, and packaged binaries. It is especially useful for developers and security teams that want a lightweight, CLI-based SBOM generator that fits easily into local development, CI/CD pipelines, and vulnerability scanning workflows. 

For teams that need robust, enterprise-scale SBOM management and compliance capabilities, opting for an enterprise solution like Anchore Enterprise offers the same foundational benefits as Syft plus continuous vulnerability scanning, automated compliance enforcement, custom reporting, and more.

Speak with our security experts

Learn how Anchore’s SBOM-powered platform can help secure your software supply chain.