name: syft
binary: syft
aliases: []
category:
- security
lang:
- all
summary: SBOM generator for container images and filesystems.
homepage: https://github.com/anchore/syft
docs: https://github.com/anchore/syft#readme
detect:
version_args:
- version
local:
files:
- .syft.yaml
dirs: []
package_json:
package_manager_prefixes: []
use_when:
- Generate software bills of materials
avoid_when:
- The scan target is unclear or too broad
risk:
level: medium
effects:
- read_files
- network_access
- write_files
requires_auth: false
destructive: false
confirmation_required_for:
- scanning sensitive directories
guardrails:
- Treat SBOMs as potentially sensitive dependency disclosure artifacts.