Getting Started
Use Syft to generate your first SBOM from container images, directories, or archives.
Use Syft to generate your first SBOM from container images, directories, or archives.
Explore the different scan targets Syft supports including container images, OCI registries, directories, files, and archives.
Choose from multiple SBOM output formats including SPDX, CycloneDX, and Syft’s native JSON format.
Learn how to work with Syft’s native JSON format including querying with jq, extracting metadata, and understanding the SBOM structure.
Configure which package catalogers Syft uses to discover software components including language-specific and file-based catalogers.
Control which files and directories Syft includes or excludes when generating SBOMs.
Create custom SBOM output formats using Go templates with available data fields to build tailored reports for specific tooling or compliance requirements.
Convert existing SBOMs between different formats including SPDX and CycloneDX using Syft’s experimental conversion capabilities.
Generate cryptographically signed SBOM attestations using in-toto and Sigstore to create, verify, and attach attestations to container images for supply chain security.