Syftvs
Trivy


Trivy: Scans and inventories in one tool, and is a CNCF project rather than single-vendor

Generates a software bill of materials from images, filesystems and archives
As of 31 August 2026, Syft is free to use. An Apache-2. Softwr lists it under Cybersecurity. Syft is made by Anchore Inc, available on macOS, Linux, Windows, Docker.
Overview
Syft scans container images, filesystems and archives and produces a software bill of materials in CycloneDX, SPDX or its own JSON format, covering more than thirty ecosystems from operating system packages through language package managers to binary classifiers. It can emit the result as an in-toto attestation for signing. What it does is inventory, and the boundary matters more here than in most tools. Syft does not enumerate CVEs; that is Grype, a separate tool from the same company that matches a bill of materials against vulnerability feeds and adds EPSS scoring, CISA KEV membership and OpenVEX filtering. Neither tool performs reachability analysis, and neither does the commercial Anchore platform above them, so nothing in this stack answers whether a vulnerable function is actually called. An inventory tells you a vulnerable version is present. It never tells you it is reachable. It is single-vendor open source. Anchore owns the repositories outright, and Syft is not a CNCF or OpenSSF project, so there is no neutral governance and no foundation holding the licence. That is a different risk profile from Sigstore next to it, and worth knowing before it becomes a compliance dependency.
The honest half
Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Syft.
Cross-shopped
Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.


Trivy: Scans and inventories in one tool, and is a CNCF project rather than single-vendor


Grype: The vulnerability matching half of the same stack, from the same company
Pricing
Taken from the vendor's own pricing page. Prices move, so check before you buy.
Syft
Free
Anchore Enterprise
On request
Capabilities
Multi-format output
CycloneDX, SPDX and Syft JSON, with conversion between them
Broad ecosystem coverage
Over thirty ecosystems from apk and dpkg through to Go, Java, Python, Rust and .NET
Binary classifiers
Identifies binaries without package metadata, though with less detail
In-toto attestations
Emits the bill of materials in a form that can be signed
Library and CLI
Usable as a Go library inside other tools as well as a command
Pairs with Grype
The same company supplies the vulnerability matching step separately
Answered, with sources
Each answer names the page it came from, so you can check it rather than take our word for it.
No. It produces an inventory. Grype, from the same company, matches that inventory against vulnerability feeds. They are separate tools and the distinction is frequently lost.
No. Neither Syft, Grype nor the commercial Anchore platform performs call graph or reachability analysis, so none of them tells you whether a vulnerable code path is actually invoked.
No. It is single-vendor open source owned by Anchore, with no foundation governance. That is a different licence risk profile from Sigstore.
Not published. The pricing page is contact-sales only, with named but unpriced commercial and federal tiers.
You largely cannot, which is the honest answer. Silent partial parsing is a known open defect, so a bill of materials used for compliance should be spot-checked against a known dependency list.
Keep looking
Signs and verifies container images and artifacts, with or without managing keys
Free public signing and transparency infrastructure for open source artifacts
Secure-by-default open source software with hardened container images and libraries
Open-source static analysis tool for finding security bugs and enforcing code standards.
AI-native ASPM platform securing AI-generated code before deployment
Free, open-source web application scanner and intercepting proxy, now governed by the Software Security Project.
Customer identity platform built around passwordless and fraud signals
Privacy management platform with regulatory research and the TRUSTe certification programme
Data security platform that maps effective permissions, content classification and access activity across file shares, Microsoft 365 and SaaS.
Cloud-delivered endpoint protection and EDR, now owned by Broadcom and positioned alongside Symantec.
Softwr does not host reviews and shows no star rating for Syft, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.
What people switch to, and what they give up
Every tier, and where the cost actually lands
Put it head to head with anything we hold
Its rating, and an embed for your own site
Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use
quoteManaged video loss prevention with human auditors for restaurants, convenience stores and retail
quoteWorkforce and customer authentication from a certificate authority
Per user per monthPrivileged access management, endpoint privilege management and secure remote access
quoteCloud video surveillance billed per camera per month, where retention length drives the bill more than anything else
Per camera per monthAI video search that runs on cameras you already own, starting near five dollars per camera per month
Per camera per monthPhishing-resistant passwordless authentication with device trust enforced at every login
quote