Syft by anchore
CLI tool and library for generating a Software Bill of Materials from container images and filesystems
About Syft
From the project's README at github.com/anchore/syft. Lightly cleaned for readability; for the full source see the upstream repo.
A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Exceptional for vulnerability detection when used with a scanner like Grype.
<img alt="Join our Discourse" src="https://img.shields.io/badge/Discourse-Join-blue?l
Health score breakdown
6-dimension composite. See methodology for formula and weights.
Adoption signals
Real-world usage data, pulled from each registry. The bigger the numbers, the more battle-tested the project.
| Signal | Value | Source |
|---|---|---|
| GitHub stars | 8.9k | github.com/anchore/syft |
| GitHub forks | 854 | github.com/anchore/syft |
| Docker Hub pulls | 9605k | hub.docker.com / anchore |
Release & maintenance
Is this project actively maintained, or about to die? Check the recency of last commit and last release.
| Project age | 6.0 years | since May 2020 |
| Last commit | 3 days ago | May 4, 2026 |
| Releases shipped | 233 | last: 6 days ago |
| Security policy | SECURITY.md | declared by maintainers |
Self-hosting cost across providers
Detected requirements: 4GB RAM, 40GB disk minimum. Cheapest plan per provider that meets the requirement.
| Provider | Plan | Specs | Monthly | |
|---|---|---|---|---|
| hetzner | CAX11 | 2c · 4GB · 40GB | $4.13 USD | Deploy → |
| vultr | VC2 | 1c · 1GB · 25GB | $5 USD | Deploy → |
| linode | Nanode 1GB | 1c · 1GB · 25GB | $5.12 USD | Deploy → |
| digitalocean | Basic Regular 1GB | 1c · 1GB · 25GB | $6 USD | Deploy → |
Security advisories
CVE-2026-33481. What people say on Hacker News
- Show HN: My OSINT dashboard with 60+ feeds now has a pseudonymous P2P comms
- Show HN: Using Telegram as an indexed system for geo-notes
- Tq-KV – Rust implementation of TurboQuant that works on GGUF models
- Manifesto on Symbiosis: A New Paradigm for Civilization Part III
- I spent a year building a GPS-ephemeral social network. Here's what happened
Ready to self-host Syft?
Spin up a hetzner CAX11 (4GB RAM, 40GB disk) for $4.13/mo and follow the project's official install docs.
Data last refreshed May 7, 2026.
Similar open-source projects
Projects in our directory that replace the same SaaS or share topics with Syft.