CLI tool and library for generating a Software Bill of Materials from container images and filesystems
Star History
Momentum
+241
STARS · LAST 30 DAYS
8
PER DAY
#102
MOST-STARRED Go
| Window | 7 days | 30 days | 90 days |
|---|---|---|---|
| Stars gained | +56 | +241 | +720 |
| Per day | 8 | 8 | 8 |
| Forks gained | +5 | +19 | +49 |
syft gained 241 stars in the last 30 days, about 8 a day, and now has 9.6K. It is about 6 years old and has averaged roughly 1.6K stars a year. It ranks #102 among Go repositories and #700 across all languages on GitHubRepo.
Trending Record
1
DAYS ON TRENDING
#1496
BEST RANK
Sep 28, 2026
FIRST APPEARANCE
Active
STATUS TODAY
syft has maintained a continuous presence across global trending indexes, peaking at #1496. Below is the 30-day activity profile:
💡 Overview
syft is an open-source project written in Go: CLI tool and library for generating a Software Bill of Materials from container images and filesystems.
Engineered for speed, consistency, and developer ease, it solves common hurdles in containers, cyclonedx, docker. It provides clear interfaces, comprehensive configuration options, and seamless integration with existing tools across the modern development stack.
⚡ Key Features
Optimized execution pipeline written in Go for predictable speed.
Zero-friction configuration with comprehensive sensible defaults out of the box.
Cross-platform runtime support across Linux, macOS, and Windows environments.
Strong typing and modular architecture designed for easy extension and maintainability.
Standardized CLI and API interfaces for smooth integration into CI/CD workflows.
Active community maintenance with regular dependency updates and security patches.
📥 Installation
$ go install github.com/anchore/syft@latest
⚙ System Requirements
Platforms
- • macOS
- • Linux
- • Windows
Runtime & Dependencies
Go >= 1.21 runtime environment
Architecture
x86_64, ARM64 (Apple Silicon & Graviton)
🧠 How It Works
syft coordinates its core functionality through a modular Go pipeline. It parses configuration parameters, validates inputs, and resolves dependencies asynchronously. By minimizing runtime overhead and keeping allocations localized, it delivers predictable performance in both local development environments and automated production workloads.
🎯 Production Use Cases
Autonomous AI Agents
Orchestrate intelligent workflows and tool-calling routines with syft.
Model Inference & Prompting
Integrate fast, local or cloud-hosted generative AI models directly into production code.
Context Memory & RAG
Augment language models with dynamic vector retrieval and structured project memory.
Developer Productivity
Automate repetitive engineering tasks, code generation, and test creation using AI agents.
🚀 Getting Started
Install syft using your package manager: `go install github.com/anchore/syft@latest`
Initialize your project workspace or configuration file for syft.
Import syft into your codebase or invoke it directly from your terminal.
Execute your test suite or run `syft --help` to verify successful setup.
👍 Strengths
⚠️ Considerations
⇄ Alternatives & Direct Competitors
👥 Who Should Use This
Developers and engineering teams building with Go, seeking reliable, tested, and actively maintained tooling for production workloads.
🏆 Nearby in the Rankings
anchore/syft is currently ranked #700 by stars across every repository tracked on GitHubRepo. These are adjacent projects:
| Rank | Repository | Language | Stars | Action |
|---|---|---|---|---|
| #694 | ashishb/android-security-awesome | Makefile | ★ 9.7K | Compare ↗ |
| #696 | kyutai-labs/pocket-tts | Python | ★ 9.7K | Compare ↗ |
| #697 | tobymao/sqlglot | Python | ★ 9.6K | Compare ↗ |
| #697 | Vincentwei1021/video-shotcraft | TypeScript | ★ 9.6K | Compare ↗ |
| #699 | reviewdog/reviewdog | Go | ★ 9.6K | Compare ↗ |
| #700 | anchore/syft This Project | Go | ★ 9.6K | |
| #701 | roboflow/rf-detr | Python | ★ 9.6K | Compare ↗ |
| #702 | v2fly/domain-list-community | Go | ★ 9.6K | Compare ↗ |
| #703 | flowable/flowable-engine | Java | ★ 9.6K | Compare ↗ |
| #704 | marcelscruz/public-apis | JavaScript | ★ 9.5K | Compare ↗ |
| #705 | litedb-org/LiteDB | C# | ★ 9.5K | Compare ↗ |
Frequently Asked Questions
What does syft do? +
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
What language is syft written in? +
The primary language is Go. Topics include: containers, cyclonedx, docker, go, golang.
Is syft actively maintained? +
Yes, the last recorded push was on Sep 28, 2026 with 660 open issues being tracked.
How many stars does syft have? +
syft has 9,620 stars and 970 forks on GitHub.
How does syft rank among GitHub repositories? +
With 9,620 stars, anchore/syft is ranked #700 globally across all repositories tracked on GitHubRepo and #102 among Go projects.
What license is syft distributed under? +
The repository reports a Apache-2.0 license. Always verify the repository LICENSE file for legal terms.