Open Source

Developer-friendly tools for software supply chain security

SBOM documentation

Syft

Syft logo
Syft logo

A CLI tool for generating a Software Bill of Materials (SBOM) from container images and filesystems.

Vulnerability scanning documentation

Grype

Grype logo
Grype logo

An easy-to-integrate open source vulnerability scanning tool for container images and filesystems.

License documentation

Grant

Grant logo
Grant logo

View licenses for containers, SBOM documents, filesystems, and apply rules that help you build a license compliance report.