Automic VaultAutomic Vault

brew / 排名 858

安装 syft

查看 syft 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

安装

使用 Automic Vault 安装

Automic Vault
下载 AV
sudo av install brew:syft

macOS

Homebrewverified · 100%
brew install syft

local Homebrew formula metadata

Linux

Alpine Linux apkverified · 92%
sudo apk add syft

Alpine Linux edge package indexes · syft · source: dl-cdn.alpinelinux.org

Nixverified · 92%
nix profile install nixpkgs#syft

nixpkgs package indexes · pkgs/by-name/sy/syft/package.nix · source: api.github.com

Arch Linux pacmanverified · 92%
sudo pacman -S syft

Arch Linux sync databases · syft · source: geo.mirror.pkgbuild.com

openSUSE zypperverified · 92%
sudo zypper install syft

openSUSE Tumbleweed package metadata · syft · source: download.opensuse.org

平台说明

  • 没有特定于此软件包的平台说明。

概览

软件包摘要

CLI for generating a Software Bill of Materials from container images

命令和别名

  • syft

安全态势

风险级别:orange

broad file, network, media, or database tool signal. infrastructure mutation or orchestration signal.

Risk classifier

orange risk · medium confidence · infrastructure

Why

  • broad file, network, media, or database tool signal
  • infrastructure mutation or orchestration signal

Signals

  • text:container
  • text:image

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Build metadata lists 1 build dependencies.

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

可执行文件

已安装的可执行文件

命令类型暴露范围备注
syftcliglobal executable

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-06-10
管理器版本1.45.1
管理器更新时间2026-06-05
本地数据ok
上游current
检测到的最新版本v1.45.1

https://github.com/anchore/syft

  • okNo freshness warnings were generated.

安装元数据

软件包元数据

Package keybrew:syft
Version1.45.1
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/syft
Homepagehttps://github.com/anchore/syft
Repositoryhttps://github.com/anchore/syft
Upstream docshttps://github.com/anchore/syft/blob/main/README.md
LicenseApache-2.0
Source archivehttps://github.com/anchore/syft/archive/refs/tags/v1.45.1.tar.gz
Last updated2026-06-05T16:16:22Z
Pulseupdated
Build dependenciesgo
Bottleavailable (arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namesyft
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

syft

nix profile install nixpkgs#syft
  • normalized package name match
  • Matched by: Syft
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/sy/syft/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
apk95%

syft 1.42.4-r1

Generate a Software Bill of Materials (SBOM) from container images and filesystems

https://github.com/anchore/syft

sudo apk add syft
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: syft
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Syft
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: syft from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
apk95%

syft-bash-completion 1.42.4-r1

Bash completions for syft

https://github.com/anchore/syft

sudo apk add syft-bash-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: syft
  • normalized package name match
  • Matched by: Syft
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: syft-bash-completion from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
apk95%

syft-fish-completion 1.42.4-r1

Fish completions for syft

https://github.com/anchore/syft

sudo apk add syft-fish-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: syft
  • normalized package name match
  • Matched by: Syft
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: syft-fish-completion from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
apk95%

syft-zsh-completion 1.42.4-r1

Zsh completions for syft

https://github.com/anchore/syft

sudo apk add syft-zsh-completion
  • License: Apache-2.0
  • Architecture: x86_64
  • Source Package: syft
  • normalized package name match
  • Matched by: Syft
Alpine Linux edge package indexes · dl-cdn.alpinelinux.org · Alpine Linux edge package indexes: syft-zsh-completion from https://dl-cdn.alpinelinux.org/alpine/edge/community/x86_64/APKINDEX.tar.gz
pacman95%

syft 1.44.0-1

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

https://github.com/anchore/syft

sudo pacman -S syft
  • License: Apache-2.0
  • Architecture: x86_64
  • 1 dependencies
  • normalized package name match
  • Matched by: Syft
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: syft from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
zypper95%

syft 1.44.0-1.1

CLI tool and library for generating a Software Bill of Materials

https://github.com/anchore/syft

sudo zypper install syft
  • License: Apache-2.0
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: syft
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Syft
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: syft from https://download.opensuse.org/tumbleweed/repo/oss/repodata/155b97171d05e27afd950b6fe0d55513ff38f4597110664535bceedc680bbe6fd459f0733718dcc21dcf0efc7c8250fd1390c73d4790b42e62fb2c16a87242e5-primary.xml.zst
zypper95%

syft-bash-completion 1.44.0-1.1

Bash Completion for syft

https://github.com/anchore/syft

sudo zypper install syft-bash-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: syft
  • 2 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Syft
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: syft-bash-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/155b97171d05e27afd950b6fe0d55513ff38f4597110664535bceedc680bbe6fd459f0733718dcc21dcf0efc7c8250fd1390c73d4790b42e62fb2c16a87242e5-primary.xml.zst
zypper95%

syft-fish-completion 1.44.0-1.1

Fish Completion for syft

https://github.com/anchore/syft

sudo zypper install syft-fish-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: syft
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Syft
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: syft-fish-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/155b97171d05e27afd950b6fe0d55513ff38f4597110664535bceedc680bbe6fd459f0733718dcc21dcf0efc7c8250fd1390c73d4790b42e62fb2c16a87242e5-primary.xml.zst
zypper95%

syft-zsh-completion 1.44.0-1.1

Zsh Completion for syft

https://github.com/anchore/syft

sudo zypper install syft-zsh-completion
  • License: Apache-2.0
  • Category: System/Shells
  • Architecture: noarch
  • Source Package: syft
  • 1 dependencies
  • 1 provides
  • normalized package name match
  • Matched by: Syft
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: syft-zsh-completion from https://download.opensuse.org/tumbleweed/repo/oss/repodata/155b97171d05e27afd950b6fe0d55513ff38f4597110664535bceedc680bbe6fd459f0733718dcc21dcf0efc7c8250fd1390c73d4790b42e62fb2c16a87242e5-primary.xml.zst
Chocolatey95%

syft

choco install syft
  • normalized package name match
  • Matched by: Syft
Chocolatey community package catalog · community.chocolatey.org · Chocolatey community package catalog: syft from http://community.chocolatey.org/api/v2/Packages?$filter=IsLatestVersion&$select=Id&$top=1000&$skiptoken='11','swissfileknife'
Scoop95%

main/syft

scoop install main/syft
  • normalized package name match
  • Matched by: Syft
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/syft.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
winget95%

Anchore.Syft

winget install --id Anchore.Syft -e
  • normalized package name match
  • Matched by: Syft
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: Anchore.Syft from https://cdn.winget.microsoft.com/cache/source.msix

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment