Syft
apartment
3 companies hiring
Radar: Initial
Apache-2.0
Generates a software bill of materials from container images and filesystems, emitting SPDX or CycloneDX — the most widely used SBOM generator there is.
SPDX
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| SPDX | generates |
The most-used SBOM generator; emits SPDX and CycloneDX.
Produces: sbom |
Using this from an agent
- Interfaces
clicontainerlibraryci-action- Install
-
brew
syftgogithub.com/anchore/syft/cmd/syft - Invoke
syft <image-or-dir> -o spdx-json=<sbom.spdx.json>- Consumes
- oci-image, filesystem
- Emits
- spdx, cyclonedx, json, table
- Runtime
- Runs offline Deterministic Writes No credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Answer "what is actually inside this image?" with a machine-readable artifact.
coding-agentci-pipeline
Where a supply-chain conversation starts. Pipe the output into Grype and the same artifact answers "and what is wrong with it?".
Produce the SBOM a customer or regulator is asking for, in the format they named.
ci-pipeline
- Website
- https://github.com/anchore/syft
- Repository
- https://github.com/anchore/syft
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-08-11
- Stars
- 9377 · last commit 2026-08-10
- Companies hiring
- 3 — distinct companies whose job postings name this tool, Q3-2026. A demand signal, not a deployment count.
Reading this as an agent? Don't scrape the page — this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.