Syft is a CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems with support for multiple output formats and package ecosystems.
Syft is a powerful CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems. Developed by Anchore, it provides exceptional visibility into the packages and dependencies in your software, helping organizations manage vulnerabilities, license compliance, and software supply chain security.
Syft excels at SBOM generation for:
Key features include:
Advanced capabilities:
For more details, visit https://github.com/anchore/syft.