{"repo":"anchore/syft","free":true,"listed":false,"github":"https://github.com/anchore/syft","clone":"git clone https://github.com/anchore/syft.git","description":"CLI tool and library for generating a Software Bill of Materials from container images and filesystems","language":"Go","stars":9417,"topics":["containers","docker","go","golang","static-analysis","tool","oci","sbom","spdx","cyclonedx"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Syft A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Exceptional for vulnerability detection when used with a scanner like Grype. &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Features - Generates SBOMs for container images , filesystems , archives (see the docs for a full list of supported scan targets) - Supports dozens of packaging ecosystems (e.g. Alpine (apk), Debian (dpkg), RPM, Go, Python, Java, JavaScript, Ruby, Rust, PHP, .NET, and many more) - Supports OCI, Docker, Singularity, and more image formats - Works seamlessly with Grype for vulnerability scanning - Multiple output formats ( CycloneDX , SPDX , Syft JSON , and more) including the ability to convert between SBOM formats - Create signed SBOM attestations using the in-toto specification [!TIP] New to Syft? Check out the Getting Started guide for a walkthrough! Installation The quickest way to get up and going: [!TIP] See Installation docs for more ways to get Syft, including Homebrew, Docker, Scoop, Chocolatey, Nix, and more! The basics See the packages within a container image or directory: To get an SBOM, specify one or more output formats: [!TIP] Check out the Getting Started guide to explore all of the capabilities and features. Want to know all of the ins-and-outs of Syft? Check out the CLI docs, configuration docs, and JSON schema. Contributing We encourage users to help make these tools better by sub","default_branch":null,"files":null,"tree":[],"storefront":"/r/anchore","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/anchore/syft/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}