# Syft

**URL:** https://anchorecommunity.discourse.group/c/syft/5.md

[Latest](https://anchorecommunity.discourse.group/latest.md) · [Categories](https://anchorecommunity.discourse.group/categories.md) · [Tags](https://anchorecommunity.discourse.group/tags.md)

---

## [About the Syft category](https://anchorecommunity.discourse.group/t/about-the-syft-category/10)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 0\
**Last updated:** [May 28, 2024, 9:56am UTC](https://anchorecommunity.discourse.group/t/about-the-syft-category/10 "2024-05-28T09:56:52Z")

</div>

Syft This category is used for discussion of Syft - the CLI tool and library for generating a Software Bill of Materials from container images and filesystems. Discussion of the development and use of Syft is on t…

---

## [Disabling Syft network calls from the CLI](https://anchorecommunity.discourse.group/t/disabling-syft-network-calls-from-the-cli/660)

<div class="topic-metadata">

**Author:** [@Jonas\_Wielage](https://anchorecommunity.discourse.group/u/Jonas_Wielage)\
**Replies:** 0\
**Last updated:** [September 15, 2026, 11:18am UTC](https://anchorecommunity.discourse.group/t/disabling-syft-network-calls-from-the-cli/660 "2026-09-15T11:18:29Z")

</div>

Hi all, I’d like to start a discussion about running syft in a fully offline mode — meaning a configuration where syft is guaranteed not to make any outbound network call. Why I need it My organization places constrai…

---

## [Vulnerability scanner as a service for linux devices using syft](https://anchorecommunity.discourse.group/t/vulnerability-scanner-as-a-service-for-linux-devices-using-syft/658)

<div class="topic-metadata">

**Author:** [@Hriday\_Pradhan](https://anchorecommunity.discourse.group/u/Hriday_Pradhan)\
**Replies:** 0\
**Last updated:** [August 18, 2026, 11:40am UTC](https://anchorecommunity.discourse.group/t/vulnerability-scanner-as-a-service-for-linux-devices-using-syft/658 "2026-08-18T11:40:57Z")

</div>

Hey everyone! I came across Syft while exploring options for a project I’m working on and it seems like it could be a great fit. Would appreciate any guidance or pointers to existing threads! Use case: We’re building a…

---

## [Syft is not listing the packages under dev\_dependencies section in package-lock.json](https://anchorecommunity.discourse.group/t/syft-is-not-listing-the-packages-under-dev-dependencies-section-in-package-lock-json/614)

<div class="topic-metadata">

**Author:** [@anvitha\_haviligi](https://anchorecommunity.discourse.group/u/anvitha_haviligi)\
**Replies:** 7\
**Last updated:** [March 25, 2026, 4:22am UTC](https://anchorecommunity.discourse.group/t/syft-is-not-listing-the-packages-under-dev-dependencies-section-in-package-lock-json/614 "2026-03-25T04:22:10Z")

</div>

We scanned nodejs git repository which has both package.json and package-lock.json, we observed packages under devdependencies are not listed in sbom. Please help us in resolving the issue. Regards, Anvitha

---

## [Missing package identification from .zap packaging](https://anchorecommunity.discourse.group/t/missing-package-identification-from-zap-packaging/599)

<div class="topic-metadata">

**Author:** [@santhosh](https://anchorecommunity.discourse.group/u/santhosh)\
**Replies:** 3\
**Last updated:** [March 6, 2026, 2:33am UTC](https://anchorecommunity.discourse.group/t/missing-package-identification-from-zap-packaging/599 "2026-03-06T02:33:14Z")

</div>

We have observed that some third party vendor softwares are using .zap packaging type for Java packages. Syft can’t parse or read package information from .zap type. Example, https://github.com/zaproxy/zaproxy/releases…

---

## [Syft is not scanning jar files which are integrated to docker image](https://anchorecommunity.discourse.group/t/syft-is-not-scanning-jar-files-which-are-integrated-to-docker-image/578)

<div class="topic-metadata">

**Author:** [@anvitha\_haviligi](https://anchorecommunity.discourse.group/u/anvitha_haviligi)\
**Replies:** 16\
**Last updated:** [October 30, 2025, 8:52pm UTC](https://anchorecommunity.discourse.group/t/syft-is-not-scanning-jar-files-which-are-integrated-to-docker-image/578 "2025-10-30T20:52:06Z")

</div>

Observed syft provides jar name in sbom file but not the components included in the jar file, example: a.jar contains pom.xml ./META-INF/maven/com.inn.a.b/a-b-app/pom.xml, used below command to generate sbom syft scan …

---

## [Corretly identifying jar file with only pom.xml](https://anchorecommunity.discourse.group/t/corretly-identifying-jar-file-with-only-pom-xml/573)

<div class="topic-metadata">

**Author:** [@douglasclarke](https://anchorecommunity.discourse.group/u/douglasclarke)\
**Replies:** 3\
**Last updated:** [October 7, 2025, 10:37pm UTC](https://anchorecommunity.discourse.group/t/corretly-identifying-jar-file-with-only-pom-xml/573 "2025-10-07T22:37:59Z")

</div>

I have seen a couple of somewhat related issues but wanted to ask specifically. As best I can read the java archive parser it looks for pom.properties and pom.xml and only uses the pom.xml (project) if the properties fil…

---

## [Should I create a template, or just post-process to get an SPDX SBOM containing PURLs only?](https://anchorecommunity.discourse.group/t/should-i-create-a-template-or-just-post-process-to-get-an-spdx-sbom-containing-purls-only/558)

<div class="topic-metadata">

**Author:** [@eherget](https://anchorecommunity.discourse.group/u/eherget)\
**Replies:** 2\
**Last updated:** [September 11, 2025, 7:48pm UTC](https://anchorecommunity.discourse.group/t/should-i-create-a-template-or-just-post-process-to-get-an-spdx-sbom-containing-purls-only/558 "2025-09-11T19:48:24Z")

</div>

I would like to have syft generate SPDX SBOMs containing PURLs only, no CPEs. My thought is that using a template would be the “clean” way to do it. The alternative is to generate an SPDX SBOM, then post-process the ou…

---

## [Components missing from CycloneDX json format SBOM when generation is part of a test](https://anchorecommunity.discourse.group/t/components-missing-from-cyclonedx-json-format-sbom-when-generation-is-part-of-a-test/553)

<div class="topic-metadata">

**Author:** [@danrollason](https://anchorecommunity.discourse.group/u/danrollason)\
**Replies:** 5\
**Last updated:** [September 9, 2025, 2:18pm UTC](https://anchorecommunity.discourse.group/t/components-missing-from-cyclonedx-json-format-sbom-when-generation-is-part-of-a-test/553 "2025-09-09T14:18:40Z")

</div>

Hi, We are using Syft as a library to generate CycloneDX json format SBOMs. Our code runs on a scratch container and works fine. We added a /tmp directory to the scratch container and in our example generates a 2000+ …

---

## [SBOM container tools comparison](https://anchorecommunity.discourse.group/t/sbom-container-tools-comparison/551)

<div class="topic-metadata">

**Author:** [@Jakub\_Bochenski](https://anchorecommunity.discourse.group/u/Jakub_Bochenski)\
**Replies:** 2\
**Last updated:** [September 9, 2025, 1:22pm UTC](https://anchorecommunity.discourse.group/t/sbom-container-tools-comparison/551 "2025-09-09T13:22:48Z")

</div>

I put together a comparison of container scanning tools: GitHub - jakub-bochenski/container-sbom-shootout: Comparison of different tools for generating CycloneDX SBOMs for container images. I’m looking for feedback — if…

---

## [Cyclonedx SBOM files do not pass cyclonedx cli validate command when SMAIL-GPL included as licenses](https://anchorecommunity.discourse.group/t/cyclonedx-sbom-files-do-not-pass-cyclonedx-cli-validate-command-when-smail-gpl-included-as-licenses/552)

<div class="topic-metadata">

**Author:** [@Diamantis\_Sellis](https://anchorecommunity.discourse.group/u/Diamantis_Sellis)\
**Replies:** 4\
**Last updated:** [September 5, 2025, 6:48pm UTC](https://anchorecommunity.discourse.group/t/cyclonedx-sbom-files-do-not-pass-cyclonedx-cli-validate-command-when-smail-gpl-included-as-licenses/552 "2025-09-05T18:48:55Z")

</div>

I am using syft version 1.32.0 to scan docker images but the resulting files do not pass validation by dependency-tracker nor by the cyclonedx-cli, so I can’t really use them, e.g. : $\> syft scan docker:nginx -o cyclone…

---

## [Reducing 'unknowns' via targeted fuzzy binary catalogers](https://anchorecommunity.discourse.group/t/reducing-unknowns-via-targeted-fuzzy-binary-catalogers/542)

<div class="topic-metadata">

**Author:** [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Replies:** 1\
**Last updated:** [August 26, 2025, 6:37am UTC](https://anchorecommunity.discourse.group/t/reducing-unknowns-via-targeted-fuzzy-binary-catalogers/542 "2025-08-26T06:37:30Z")

</div>

A question for you on the topic of binary fingerprinting like the recent ffmpeg one. tl;dr; Some ecosystems of different software containers have numerous, common “unknown unknowns” in their SBOMs. Would it be advantage…

---

## [PURL is empty for "graalvm-native-image-cataloger"](https://anchorecommunity.discourse.group/t/purl-is-empty-for-graalvm-native-image-cataloger/535)

<div class="topic-metadata">

**Author:** [@santhosh](https://anchorecommunity.discourse.group/u/santhosh)\
**Replies:** 5\
**Last updated:** [August 20, 2025, 5:21pm UTC](https://anchorecommunity.discourse.group/t/purl-is-empty-for-graalvm-native-image-cataloger/535 "2025-08-20T17:21:56Z")

</div>

I am generating SBOM for graal-vm-native binaries. I have created a simple maven project with few dependencies. downloaded graalvm-jdk-21 Built maven project using mvn clean package Generated native binary using comman…

---

## [Vcpkg custom registry](https://anchorecommunity.discourse.group/t/vcpkg-custom-registry/532)

<div class="topic-metadata">

**Author:** [@gabetrau](https://anchorecommunity.discourse.group/u/gabetrau)\
**Replies:** 5\
**Last updated:** [August 18, 2025, 3:13pm UTC](https://anchorecommunity.discourse.group/t/vcpkg-custom-registry/532 "2025-08-18T15:13:08Z")

</div>

Could someone initialize a project for me here anchore/vcpkg-test-fixture · GitHub ? It won’t let me make a pull request since it’s empty

---

## [Why is syft reporting hundreds of random files?](https://anchorecommunity.discourse.group/t/why-is-syft-reporting-hundreds-of-random-files/515)

<div class="topic-metadata">

**Author:** [@Jakub\_Bochenski](https://anchorecommunity.discourse.group/u/Jakub_Bochenski)\
**Replies:** 2\
**Last updated:** [July 31, 2025, 11:31am UTC](https://anchorecommunity.discourse.group/t/why-is-syft-reporting-hundreds-of-random-files/515 "2025-07-31T11:31:23Z")

</div>

I get 1K+ file entries that seem uninteresting, some examples: /usr/share/zoneinfo/zone.tab - random linux configuration files /usr/share/doc/libssl3/copyright - random text files /usr/lib/x86\_64-linux-gnu/gconv/IBM423…

---

## [Future of mholt/archiver fork?](https://anchorecommunity.discourse.group/t/future-of-mholt-archiver-fork/511)

<div class="topic-metadata">

**Author:** [@danrollason](https://anchorecommunity.discourse.group/u/danrollason)\
**Replies:** 1\
**Last updated:** [July 25, 2025, 1:13pm UTC](https://anchorecommunity.discourse.group/t/future-of-mholt-archiver-fork/511 "2025-07-25T13:13:23Z")

</div>

Hi, Our Sonatype Nexus is reporting a problem with anchore/archiver/v3 library claiming it is vulnerable to CVE-2024-0406. Looking at the pinned forks issue on GitHub, the message suggests there is a fix for this CVE i…

---

## [Errors when using the syft image in a Cloud pipeline](https://anchorecommunity.discourse.group/t/errors-when-using-the-syft-image-in-a-cloud-pipeline/483)

<div class="topic-metadata">

**Author:** [@yener-azs](https://anchorecommunity.discourse.group/u/yener-azs)\
**Replies:** 2\
**Last updated:** [June 30, 2025, 2:19pm UTC](https://anchorecommunity.discourse.group/t/errors-when-using-the-syft-image-in-a-cloud-pipeline/483 "2025-06-30T14:19:08Z")

</div>

Hello, We want to generate the SBOM files for our python artifacts during CI using syft. The source code is in Github and the for CI we use GCP Cloud Build. Them step(job) of building the artifacts is fine. The artifact…

---

## [Support SBOM addition and subtraction](https://anchorecommunity.discourse.group/t/support-sbom-addition-and-subtraction/473)

<div class="topic-metadata">

**Author:** [@laoshanxi](https://anchorecommunity.discourse.group/u/laoshanxi)\
**Replies:** 3\
**Last updated:** [June 23, 2025, 10:07am UTC](https://anchorecommunity.discourse.group/t/support-sbom-addition-and-subtraction/473 "2025-06-23T10:07:18Z")

</div>

In many cases, in order to reflect actually software dependency introduce, we need scan base and scan finally package, but we do not want to measure base. SBOM\_full - SBOM\_base = SBOM\_real if we could support such add/…

---

## [For scan C++ binary, how to recognize the package which the binary come from](https://anchorecommunity.discourse.group/t/for-scan-c-binary-how-to-recognize-the-package-which-the-binary-come-from/433)

<div class="topic-metadata">

**Author:** [@laoshanxi](https://anchorecommunity.discourse.group/u/laoshanxi)\
**Replies:** 5\
**Last updated:** [June 21, 2025, 8:07am UTC](https://anchorecommunity.discourse.group/t/for-scan-c-binary-how-to-recognize-the-package-which-the-binary-come-from/433 "2025-06-21T08:07:36Z")

</div>

if my C++ package directory contain a boost library like \<libboost\_filesystem.so.1.83.0\>, can syft recognize the package as well?

---

## [How to scan 2 directories at one time](https://anchorecommunity.discourse.group/t/how-to-scan-2-directories-at-one-time/461)

<div class="topic-metadata">

**Author:** [@laoshanxi](https://anchorecommunity.discourse.group/u/laoshanxi)\
**Replies:** 2\
**Last updated:** [June 18, 2025, 1:41am UTC](https://anchorecommunity.discourse.group/t/how-to-scan-2-directories-at-one-time/461 "2025-06-18T01:41:49Z")

</div>

how to scan 2 directory at one time

---

## [Limiting the number of threads used](https://anchorecommunity.discourse.group/t/limiting-the-number-of-threads-used/442)

<div class="topic-metadata">

**Author:** [@jkugler](https://anchorecommunity.discourse.group/u/jkugler)\
**Replies:** 3\
**Last updated:** [May 20, 2025, 6:58pm UTC](https://anchorecommunity.discourse.group/t/limiting-the-number-of-threads-used/442 "2025-05-20T18:58:34Z")

</div>

Is there a way to limit the number of threads Syft will use? We are running Syft in a container, and sometimes we get the error: failed to create new os thread (have 24 already; errno=11) may need to increase max user p…

---

## [Package detect, binary NOT detect](https://anchorecommunity.discourse.group/t/package-detect-binary-not-detect/299)

<div class="topic-metadata">

**Author:** [@witchcraze](https://anchorecommunity.discourse.group/u/witchcraze)\
**Replies:** 5\
**Last updated:** [April 15, 2025, 1:09pm UTC](https://anchorecommunity.discourse.group/t/package-detect-binary-not-detect/299 "2025-04-15T13:09:37Z")

</div>

Hi, I notice a case - package is detected, but binary is NOT detected. php packages including php-cli are detected $ syft -q cimg/php:5.6.40 | grep php libapache2-mod-php5.6 5.6.40-29+ubuntu18.04.1+deb.sur…

---

## [Squash with all layers pr](https://anchorecommunity.discourse.group/t/squash-with-all-layers-pr/399)

<div class="topic-metadata">

**Author:** [@TimBrown1611](https://anchorecommunity.discourse.group/u/TimBrown1611)\
**Replies:** 0\
**Last updated:** [April 7, 2025, 12:31pm UTC](https://anchorecommunity.discourse.group/t/squash-with-all-layers-pr/399 "2025-04-07T12:31:10Z")

</div>

hello all, I’m reaching out to find what is the status on this pr - Squashed all layers by tomersein · Pull Request #3138 · anchore/syft · GitHub it will be really helpful to understand if there is a chance it will be …

---

## [.NET NuGet ecosystem support](https://anchorecommunity.discourse.group/t/net-nuget-ecosystem-support/396)

<div class="topic-metadata">

**Author:** [@ale](https://anchorecommunity.discourse.group/u/ale)\
**Replies:** 0\
**Last updated:** [April 7, 2025, 9:00am UTC](https://anchorecommunity.discourse.group/t/net-nuget-ecosystem-support/396 "2025-04-07T09:00:41Z")

</div>

Hi We have various container images that contain C# .net applications that utilize PackageReference to specify and pull NuGet dependencies from various repositories. Is that supported by sift ? On the github page only …

---

## [Add OS related information on language based packages](https://anchorecommunity.discourse.group/t/add-os-related-information-on-language-based-packages/379)

<div class="topic-metadata">

**Author:** [@santhosh](https://anchorecommunity.discourse.group/u/santhosh)\
**Replies:** 0\
**Last updated:** [March 25, 2025, 3:40pm UTC](https://anchorecommunity.discourse.group/t/add-os-related-information-on-language-based-packages/379 "2025-03-25T15:40:41Z")

</div>

Today, Syft adds OS related info like arch, distro, os version for RPM packages only. But if a python is installed as an rpm then it is identified twice. Once as a rpm and second one as a language/binary package. OS info…

---

## [Understanding Syft's Software Detection Mechanism and Architecture](https://anchorecommunity.discourse.group/t/understanding-syfts-software-detection-mechanism-and-architecture/378)

<div class="topic-metadata">

**Author:** [@ravi\_kumar](https://anchorecommunity.discourse.group/u/ravi_kumar)\
**Replies:** 0\
**Last updated:** [March 25, 2025, 12:36pm UTC](https://anchorecommunity.discourse.group/t/understanding-syfts-software-detection-mechanism-and-architecture/378 "2025-03-25T12:36:52Z")

</div>

Hi, I am new to the Syft tool and am interested in understanding its software detection mechanism. Is there any available documentation on its architecture or workflow? I have not been able to find one online.

---

## [Does Syft automaticaly detects existing SBOM files?](https://anchorecommunity.discourse.group/t/does-syft-automaticaly-detects-existing-sbom-files/372)

<div class="topic-metadata">

**Author:** [@gillg](https://anchorecommunity.discourse.group/u/gillg)\
**Replies:** 1\
**Last updated:** [March 20, 2025, 7:06pm UTC](https://anchorecommunity.discourse.group/t/does-syft-automaticaly-detects-existing-sbom-files/372 "2025-03-20T19:06:38Z")

</div>

Assuming I use another tool thant Syft for more accurate SBOM generation during the build of my application (less hidden dependancies, and deeper scaning of licences and libs), if the SBOM (JSON Spdx for example) is pres…

---

## [What are the plans for metadata in the syft format](https://anchorecommunity.discourse.group/t/what-are-the-plans-for-metadata-in-the-syft-format/318)

<div class="topic-metadata">

**Author:** [@henrysachs](https://anchorecommunity.discourse.group/u/henrysachs)\
**Replies:** 6\
**Last updated:** [March 17, 2025, 3:19pm UTC](https://anchorecommunity.discourse.group/t/what-are-the-plans-for-metadata-in-the-syft-format/318 "2025-03-17T15:19:48Z")

</div>

SPDX and Cyclone DX have field for additional metadata so pass in. My Organisation faces similiar problems they want to solve with the metadata. For Example “tag” the Team that created the SBOM. What are the plans for th…

---

## [How long should syft really take?](https://anchorecommunity.discourse.group/t/how-long-should-syft-really-take/345)

<div class="topic-metadata">

**Author:** [@billy\_muller\_cyera](https://anchorecommunity.discourse.group/u/billy_muller_cyera)\
**Replies:** 6\
**Last updated:** [March 3, 2025, 5:59pm UTC](https://anchorecommunity.discourse.group/t/how-long-should-syft-really-take/345 "2025-03-03T17:59:47Z")

</div>

Hi, I’m working on some automation to create SBOMs for my container images, some images are quite large (300Mb +) and it’s taking forever, literally hours. I’m running this in AWS on an 8 core 8GB RAM machine, I’ve incr…

---

## [How to help development teams to fix vulnerable packages identified by Syft?](https://anchorecommunity.discourse.group/t/how-to-help-development-teams-to-fix-vulnerable-packages-identified-by-syft/334)

<div class="topic-metadata">

**Author:** [@caio.cfonseca](https://anchorecommunity.discourse.group/u/caio.cfonseca)\
**Replies:** 2\
**Last updated:** [February 22, 2025, 1:23am UTC](https://anchorecommunity.discourse.group/t/how-to-help-development-teams-to-fix-vulnerable-packages-identified-by-syft/334 "2025-02-22T01:23:27Z")

</div>

Hello, I am currently using a combination of Syft (for generating SBOMs) + Dependency-Track as our SCA solution. This combination works fine but I am having trouble helping the development teams to fix vulnerabilities be…

[Next page](https://anchorecommunity.discourse.group/c/syft/5.md?page=1)
