syft

syft - A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

View Repository
8527 Stars
780 Forks
Apache-2.0 License
Go Language
2026-03-18 Last Update
541 Open Issues
containers cyclonedx docker go golang hacktoberfest oci sbom spdx static-analysis tool
← All Package Management