syft
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
About this project
Syft A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Exceptional for vulnerability detection when used with a scanner like Grype. Features — Generates SBOMs for container images, filesystems, archives (see the docs for a full list of supported scan targets) — Supports dozens of packaging ecosystems (e.g. Alpine (apk), Debian (dpkg), RPM, Go, Python, Java, JavaScript, Ruby, Rust, PHP, .NET, and many more) — Supports OCI, Docker, Singularity, and more image formats — Works seamlessly with Grype for vulnerability scanning —…
Technologies
Project health
GitHub
Reviews
Built by
Maintain anchore/syft? Claiming verifies admin access through your GitHub account and gives you control of this listing.

