Built something? We create video reels & spotlights for GitHub projects.Promote your project →
anchore
Home / Go / syft

anchore/syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Go ◇ containers Apache-2.0
★9.6KSTARS
⑂970FORKS
!660ISSUES
🏆#700GLOBAL RANK
🔥1DAYS TRENDING
🚀
Maintainer Growth Kit for syft

Claim this project, add your verified backlink badge to your README, and download milestone cards.

Claim Repo

Star History

Continuous Observations
Interactive star growth chart for anchore/syft
CSV

Momentum

+241

STARS · LAST 30 DAYS

8

PER DAY

#102

MOST-STARRED Go

Window7 days30 days90 days
Stars gained+56+241+720
Per day888
Forks gained+5+19+49

syft gained 241 stars in the last 30 days, about 8 a day, and now has 9.6K. It is about 6 years old and has averaged roughly 1.6K stars a year. It ranks #102 among Go repositories and #700 across all languages on GitHubRepo.

Trending Record

syft has maintained a continuous presence across global trending indexes, peaking at #1496. Below is the 30-day activity profile:

💡 Overview

syft is an open-source project written in Go: CLI tool and library for generating a Software Bill of Materials from container images and filesystems.

Engineered for speed, consistency, and developer ease, it solves common hurdles in containers, cyclonedx, docker. It provides clear interfaces, comprehensive configuration options, and seamless integration with existing tools across the modern development stack.

⚡ Key Features

1

Optimized execution pipeline written in Go for predictable speed.

2

Zero-friction configuration with comprehensive sensible defaults out of the box.

3

Cross-platform runtime support across Linux, macOS, and Windows environments.

4

Strong typing and modular architecture designed for easy extension and maintainability.

5

Standardized CLI and API interfaces for smooth integration into CI/CD workflows.

6

Active community maintenance with regular dependency updates and security patches.

📥 Installation

terminal
$ go install github.com/anchore/syft@latest

⚙ System Requirements

Platforms

  • • macOS
  • • Linux
  • • Windows

Runtime & Dependencies

Go >= 1.21 runtime environment

Architecture

x86_64, ARM64 (Apple Silicon & Graviton)

🧠 How It Works

syft coordinates its core functionality through a modular Go pipeline. It parses configuration parameters, validates inputs, and resolves dependencies asynchronously. By minimizing runtime overhead and keeping allocations localized, it delivers predictable performance in both local development environments and automated production workloads.

🎯 Production Use Cases

Autonomous AI Agents

Orchestrate intelligent workflows and tool-calling routines with syft.

Model Inference & Prompting

Integrate fast, local or cloud-hosted generative AI models directly into production code.

Context Memory & RAG

Augment language models with dynamic vector retrieval and structured project memory.

Developer Productivity

Automate repetitive engineering tasks, code generation, and test creation using AI agents.

🚀 Getting Started

1

Install syft using your package manager: `go install github.com/anchore/syft@latest`

2

Initialize your project workspace or configuration file for syft.

3

Import syft into your codebase or invoke it directly from your terminal.

4

Execute your test suite or run `syft --help` to verify successful setup.

👍 Strengths

Active community backing with 9,620 GitHub stars and verified adoption.
Permissive open-source distribution under the Apache-2.0 license.
Built in Go for high execution speed and developer familiarity.
Cross-platform compatibility across modern Linux, macOS, and Windows environments.
Clean modular design allowing flexible configuration and pipeline integration.

⚠️ Considerations

Requires familiarity with Go and modern CLI workflows.
Ecosystem extensions may require manual configuration depending on environment constraints.
Active development roadmap means breaking API changes may occur across major versions.

⇄ Alternatives & Direct Competitors

A
avelino/awesome-go ★ 185.9K Go

A curated list of awesome Go frameworks, libraries and software

Compare ↗
O
ollama/ollama ★ 181.8K Go

Get up and running with Kimi, GLM, MiniMax, DeepSeek, gpt-oss, Qwen, Gemma and other models.

Compare ↗
G
golang/go ★ 139.1K Go

The Go programming language

Compare ↗
K
kubernetes/kubernetes ★ 128K Go

Production-Grade Container Scheduling and Management

Compare ↗

👥 Who Should Use This

Developers and engineering teams building with Go, seeking reliable, tested, and actively maintained tooling for production workloads.

🏆 Nearby in the Rankings

anchore/syft is currently ranked #700 by stars across every repository tracked on GitHubRepo. These are adjacent projects:

RankRepositoryLanguageStarsAction
#694 ashishb/android-security-awesome Makefile ★ 9.7K Compare ↗
#696 kyutai-labs/pocket-tts Python ★ 9.7K Compare ↗
#697 tobymao/sqlglot Python ★ 9.6K Compare ↗
#697 Vincentwei1021/video-shotcraft TypeScript ★ 9.6K Compare ↗
#699 reviewdog/reviewdog Go ★ 9.6K Compare ↗
#700 anchore/syft This Project Go ★ 9.6K
#701 roboflow/rf-detr Python ★ 9.6K Compare ↗
#702 v2fly/domain-list-community Go ★ 9.6K Compare ↗
#703 flowable/flowable-engine Java ★ 9.6K Compare ↗
#704 marcelscruz/public-apis JavaScript ★ 9.5K Compare ↗
#705 litedb-org/LiteDB C# ★ 9.5K Compare ↗

Frequently Asked Questions

What does syft do? +

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

What language is syft written in? +

The primary language is Go. Topics include: containers, cyclonedx, docker, go, golang.

Is syft actively maintained? +

Yes, the last recorded push was on Sep 28, 2026 with 660 open issues being tracked.

How many stars does syft have? +

syft has 9,620 stars and 970 forks on GitHub.

How does syft rank among GitHub repositories? +

With 9,620 stars, anchore/syft is ranked #700 globally across all repositories tracked on GitHubRepo and #102 among Go projects.

What license is syft distributed under? +

The repository reports a Apache-2.0 license. Always verify the repository LICENSE file for legal terms.

From our network
FOR MAINTAINERS

Built something? Put it in front of millions of developers.

We make a short reel about your project and post it across YouTube, Instagram, Threads, and X. Send a link, we do the rest.