Icon

Syft

Syft is an open source CLI tool and Go library that generates a Software Bill of Materials (SBOM) from source code, container images, and packaged binaries.
Latest: 2.1.2
Last checked: Jun 9, 2026 12:10am
Rank: 228/15140
Monitored via:
GitHub Releases Site Monitor Winget
Follow to track new versions in your feed.
Report

Overview

0
License: Apache-2.0Winget: Available

Version & Lifecycle

0
Current: 2.1.2 N-2: 1.43.0 Avg cadence: Every 12 days

Top Contributors

Top sitewide contributors:

  1. Anbarasan
  2. nico_k
  3. Bob
  4. Vigneshwaran

Community Notes

Deployment note • March 12, 2026
0

Syft official Windows release deployment note

For managed Windows deployments of Syft, use Anchore’s official release assets instead of building the deployment around a third-party package feed. The official GitHub releases include a Windows x64 ZIP named like syft_VERSION_windows_amd64.zip; extract syft.exe to a managed tools directory such as C:Program FilesSyft, add that directory to the machine PATH if needed, and use syft version as a simple post-install verification command.

For updates, replace the managed syft.exe from the newer official release ZIP and rerun syft version in the same deployment context that inventory or SBOM-generation jobs use. Official source: Anchore Syft releases.

Release Notes & Updates

0
Avg cadence:
Updates • 0

Help us match vulnerabilities

No vulnerability match yet. Pick the right product:

Looking for matching products…
Don’t see it? Paste a CPE

Also known as

Other names people use for this app — helps search and matching.

Syftanchore Syft