dhi.io/syft
Syft is a CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems with support for multiple output formats and package ecosystems.
Syft is a powerful CLI tool and Go library for generating Software Bill of Materials (SBOM) from container images and filesystems. Developed by Anchore, it provides exceptional visibility into the packages and dependencies in your software, helping organizations manage vulnerabilities, license compliance, and software supply chain security.
Syft excels at SBOM generation for:
Key features include:
Advanced capabilities:
For more details, visit https://github.com/anchore/syft.
Docker Hardened Images are built to meet the highest security and compliance standards. They provide a trusted foundation for containerized workloads by incorporating security best practices from the start.
These images are published with zero-known CVEs, include signed provenance, and come with a complete Software Bill of Materials (SBOM) and VEX metadata. They're designed to secure your software supply chain while fitting seamlessly into existing Docker workflows.
Anchore Syft is a trademark of Anchore, Inc. All rights in the mark are reserved to Anchore, Inc. Any use by Docker is for referential purposes only and does not indicate sponsorship, endorsement, or affiliation.
Try DHI Enterprise
Start a free 30-day DHI Enterprise trial to mirror this image to your organization's registry and unlock full benefits.
SLA-backed CVE remediations
FIPS & STIG-compliant variants
Customizations at enterprise scale
Distribution:
Packages
372
Vulnerabilities
Syft 1.x (fips, dev)
Updated: 1 day ago
Syft 1.x (fips)
Updated: 4 hours ago
Syft 1.x (dev)
Updated: 1 day ago
Syft 1.x
Updated: 3 days ago
Syft 1.x (fips, dev)
Updated: 6 days ago
Join GitHub Discussions or our Slack community to share ideas, ask questions, and connect with the team.
Go to discussionsJoin community