How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Syft

apartment 3 companies hiring Radar: Initial Apache-2.0

Generates a software bill of materials from container images and filesystems, emitting SPDX or CycloneDX — the most widely used SBOM generator there is.

SPDX

Specifications it implements

What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.

StandardRoleWhat that means
SPDX generates The most-used SBOM generator; emits SPDX and CycloneDX.
Produces: sbom
Using this from an agent
Interfaces
clicontainerlibraryci-action
Install
brew syft
go github.com/anchore/syft/cmd/syft
Invoke
syft <image-or-dir> -o spdx-json=<sbom.spdx.json>
Consumes
oci-image, filesystem
Emits
spdx, cyclonedx, json, table
Runtime
Runs offline Deterministic Writes No credentials

Where it applies

Jobs this tool actually does, and the surface each one is exercised on.

Answer "what is actually inside this image?" with a machine-readable artifact.
coding-agentci-pipeline

Where a supply-chain conversation starts. Pipe the output into Grype and the same artifact answers "and what is wrong with it?".

Produce the SBOM a customer or regulator is asking for, in the format they named.
ci-pipeline
Website
https://github.com/anchore/syft
Repository
https://github.com/anchore/syft
License
Apache-2.0 — reported by the GitHub API, verified 2026-08-11
Stars
9377 · last commit 2026-08-10
Companies hiring
3 — distinct companies whose job postings name this tool, Q3-2026. A demand signal, not a deployment count.
Reading this as an agent? Don't scrape the page — this entry is published as structured data at /tools.json, against the tool.schema.json schema, using the roles.json vocabulary. Start at /llms.txt.
arrow_back All tools by adoption