Sbom Syft · AgentSecOps/SecOpsAgentKit

Generate SBOMs for containers and codebases with Syft

Runs Syft to generate a Software Bill of Materials from container images, filesystems, or archives, covering 28+ package ecosystems and outputting CycloneDX, SPDX, or syft-json. Useful for vulnerability scanning, license tracking, and supply-chain audits.

Good for

  • Generate an SBOM for a Docker image
  • List packages in a project directory as CycloneDX
  • Prepare an SBOM for a vulnerability scan
Category
Coding

Open-source skills are maintained by their authors and listed as published, with attribution. Results depend on how well the skill fits your task and material.

A good place to start

Generate a CycloneDX SBOM for this Docker image and list all detected packages.

Make your next great thing.

Bring a question, a file, or an idea that’s not quite there yet.