Alternatives to Syft
Generate software bills of materials from images and files. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
Syft
Generate software bills of materials from images and files.
Replacements
Listings that take over the same core job as Syft.
Trivy
Scan software and infrastructure for known security issues.
Trivy scans containers, filesystems and configuration for known security issues, so it goes further than inventory, while remaining Apache-2.0 licensed and cross-platform.
Similar software
Related functionality, not a direct replacement.
Grype
Find known vulnerabilities in container images and filesystems.
Dependency-Track
Track component risk using software bills of materials.
OSV-Scanner
Check project dependencies against the OSV vulnerability database.
Dependency-Check
OWASP scanner that finds known vulnerabilities in a project's dependencies.
Harbor
A self-hosted container registry with vulnerability scanning, image signing and role-based access control.