syft

syft - A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

View Repository
8572 Stars
788 Forks
Apache-2.0 License
Go Language
2026-03-26 Last Update
548 Open Issues
containers cyclonedx docker go golang hacktoberfest oci sbom spdx static-analysis tool
← All Package Management