Softwr
Syft logo

Syft

Generates a software bill of materials from images, filesystems and archives

As of 31 August 2026, Syft is free to use. An Apache-2. Softwr lists it under Cybersecurity. Syft is made by Anchore Inc, available on macOS, Linux, Windows, Docker.

Overview

What Syft does

Syft scans container images, filesystems and archives and produces a software bill of materials in CycloneDX, SPDX or its own JSON format, covering more than thirty ecosystems from operating system packages through language package managers to binary classifiers. It can emit the result as an in-toto attestation for signing. What it does is inventory, and the boundary matters more here than in most tools. Syft does not enumerate CVEs; that is Grype, a separate tool from the same company that matches a bill of materials against vulnerability feeds and adds EPSS scoring, CISA KEV membership and OpenVEX filtering. Neither tool performs reachability analysis, and neither does the commercial Anchore platform above them, so nothing in this stack answers whether a vulnerable function is actually called. An inventory tells you a vulnerable version is present. It never tells you it is reachable. It is single-vendor open source. Anchore owns the repositories outright, and Syft is not a CNCF or OpenSSF project, so there is no neutral governance and no foundation holding the licence. That is a different risk profile from Sigstore next to it, and worth knowing before it becomes a compliance dependency.

What people use it for

  • Producing a bill of materials for a customer or regulator that requires one
  • Feeding an inventory into a vulnerability scanner rather than scanning images directly
  • Recording what shipped in a build so a future disclosure can be answered quickly
  • Public sector work where an SBOM is a contractual deliverable

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Syft.

  • Lockfile parsing can drop packages silently. An open issue filed in August 2026 reports the yarn v1 cataloguer returning 118 of 745 packages with no error raised, which means a complete bill of materials and an 84 percent incomplete one look identical to the caller.
  • Fidelity varies sharply by ecosystem. Conan for C and C++, Haskell and Terraform get cataloguer support with no licence data, no dependency relationships and no file ownership, so a C and C++ shop gets the least from it.
  • Binary classification yields no licence or dependency metadata, and vendored or statically linked code is exactly where supply chain risk hides, so the blind spot and the risk overlap.
  • Incorrect CPE values and CPE collisions are recorded as open issues, and since Grype matches on CPE and PURL, an inventory error becomes a false negative in the security report downstream.
  • An inventory is not a risk assessment. Even a perfect bill of materials says a vulnerable version is present, never that the vulnerable function is called, and the triage burden lands entirely on the reader.

Cross-shopped

What people choose instead of Syft

Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.

  • Syft logo
    Syft
    vs
    Trivy logo
    Trivy

    Trivy: Scans and inventories in one tool, and is a CNCF project rather than single-vendor

  • Syft logo
    Syft
    vs
    Grype logo
    Grype

    Grype: The vulnerability matching half of the same stack, from the same company

Pricing

What Syft costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

Syft

Free

  • Apache-2.0
  • No usage limits
  • Community support
  • Grype available separately on the same terms

Anchore Enterprise

On request

  • Policy enforcement and reporting
  • Federal and commercial tiers
  • Pricing not published, quoted on request

Capabilities

Features

  • Multi-format output

    CycloneDX, SPDX and Syft JSON, with conversion between them

  • Broad ecosystem coverage

    Over thirty ecosystems from apk and dpkg through to Go, Java, Python, Rust and .NET

  • Binary classifiers

    Identifies binaries without package metadata, though with less detail

  • In-toto attestations

    Emits the bill of materials in a form that can be signed

  • Library and CLI

    Usable as a Go library inside other tools as well as a command

  • Pairs with Grype

    The same company supplies the vulnerability matching step separately

Answered, with sources

Questions people ask

Each answer names the page it came from, so you can check it rather than take our word for it.

Does Syft find vulnerabilities?

No. It produces an inventory. Grype, from the same company, matches that inventory against vulnerability feeds. They are separate tools and the distinction is frequently lost.

Does anything in the Anchore stack do reachability analysis?

No. Neither Syft, Grype nor the commercial Anchore platform performs call graph or reachability analysis, so none of them tells you whether a vulnerable code path is actually invoked.

Is it a CNCF or OpenSSF project?

No. It is single-vendor open source owned by Anchore, with no foundation governance. That is a different licence risk profile from Sigstore.

What does Anchore Enterprise cost?

Not published. The pricing page is contact-sales only, with named but unpriced commercial and federal tiers.

How do I know my SBOM is complete?

You largely cannot, which is the honest answer. Silent partial parsing is a known open defect, so a bill of materials used for compliance should be spot-checked against a known dependency list.

Share

Keep looking

Where to go from Syft

Best Cybersecurity software for

Compare Syft with

Other Cybersecurity software

  • Signs and verifies container images and artifacts, with or without managing keys

    Open source12 researched notes
  • Free public signing and transparency infrastructure for open source artifacts

    Open source12 researched notes
  • Open-source vulnerability and misconfiguration scanner

    Open source7 researched notes
  • Secure-by-default open source software with hardened container images and libraries

    Free, then $19,000/yr11 researched notes
  • The world's most used penetration testing framework

    Free plan11 researched notes
  • The world's foremost network protocol analyzer

    Free plan8 researched notes
  • Open-source static analysis tool for finding security bugs and enforcing code standards.

    Free, then $30/mo10 researched notes
  • AI-native ASPM platform securing AI-generated code before deployment

    Pricing on request12 researched notes
  • Free, open-source web application scanner and intercepting proxy, now governed by the Software Security Project.

    Free plan14 researched notes
  • Manage secrets and protect sensitive data

    Free plan11 researched notes
  • Open source password management for everyone

    Free, then $1.65/mo12 researched notes
  • Security infrastructure for developers and AI agents

    Free, then $20/mo10 researched notes
  • Network vulnerability scanner

    Free plan16 researched notes
  • Customer identity platform built around passwordless and fraud signals

    Pricing on request11 researched notes
  • Privacy management platform with regulatory research and the TRUSTe certification programme

    Pricing on request13 researched notes
  • Data security platform that maps effective permissions, content classification and access activity across file shares, Microsoft 365 and SaaS.

    From $100/yr14 researched notes
  • Cloud-delivered endpoint protection and EDR, now owned by Broadcom and positioned alongside Symantec.

    14 researched notes
  • The world's foremost network protocol analyzer

    Free plan8 researched notes

Softwr does not host reviews and shows no star rating for Syft, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on Syft

Best Cybersecurity software alternatives

Privileged access management from the merged Thycotic and Centrify

quote

Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use

quote

Managed video loss prevention with human auditors for restaurants, convenience stores and retail

quote

Privileged access management, endpoint privilege management and secure remote access

quote

Cloud video surveillance billed per camera per month, where retention length drives the bill more than anything else

Per camera per month

AI video search that runs on cameras you already own, starting near five dollars per camera per month

Per camera per month

Phishing-resistant passwordless authentication with device trust enforced at every login

quote

Compare Syft with alternatives