Perform data science on data that remains in someone else's server
-
Updated
Sep 17, 2026 - Python
Perform data science on data that remains in someone else's server
Scans Software Bill of Materials (SBOMs) for security vulnerabilities
The official Syft worker for Web and Node, built in Javascript
The official Syft worker for secure on-device machine learning
Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations
Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.
AI-powered vulnerability triage platform for Python projects. KIRTA combines SBOM, SCA, static code analysis, call maps, and AI explanations to prioritize reachable security risks.
Defines types for all Serde encoding across languages
BomLens — a local-first SBOM generator & open-source risk assessor (CycloneDX). Produce an SBOM, an open-source notice, and a security/license risk report from source code, containers, binaries, firmware, or an SBOM you received. CLI or web UI, no SaaS.
Practical Cybersecurity Supply Chain Risk Management
Инструмент для безопасной генерации, анализа и форматирования Software Bill of Materials (SBOM).
Ansible role for 'syft'. Available on Ansible Galaxy.
A demonstration of how GoReleaser can help us to make software supply chain more secure by using bunch of tools such as cosign, syft, grype, slsa-provenance
AegisFlow is a threat-aware CI/CD pipeline that integrates real-time threat intelligence (AlienVault OTX), MITRE ATT&CK-based static analysis, and SBOM-driven CVE detection to automate secure software delivery.
To associate your repository with the syft topic, visit your repo's landing page and select "manage topics."