# Syft SBOM Generator (`ayeeyee/syft-sbom-generator`) Actor

Generate a real, standards-compliant SBOM (Software Bill of Materials) for a container image or git repository using Syft, in CycloneDX or SPDX format. Get a full dependency inventory covering OS packages and application libraries across every major ecosystem. $0.49 per generated SBOM.

- **URL**: https://apify.com/ayeeyee/syft-sbom-generator.md
- **Developed by:** [Virtual Footprint LLC](https://apify.com/ayeeyee) (community)
- **Categories:** Developer tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $490.00 / 1,000 sbom generateds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

<p align="center">
<img src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMjAwIiBoZWlnaHQ9IjMyMCIgdmlld0JveD0iMCAwIDEyMDAgMzIwIiByb2xlPSJpbWciIGFyaWEtbGFiZWxsZWRieT0idGl0bGUgZGVzYyI+CiAgPHRpdGxlIGlkPSJ0aXRsZSI+U3lmdCBTQk9NIEdlbmVyYXRvcjwvdGl0bGU+CiAgPGRlc2MgaWQ9ImRlc2MiPlJlYWwgQ3ljbG9uZURYIC8gU1BEWCBiaWxsIG9mIG1hdGVyaWFscywgbm90IGEgZ3Vlc3M8L2Rlc2M+CiAgPGRlZnM+CiAgICA8bGluZWFyR3JhZGllbnQgaWQ9ImVkZ2UiIHgxPSIwIiB5MT0iMCIgeDI9IjEiIHkyPSIxIj4KICAgICAgPHN0b3Agb2Zmc2V0PSIwIiBzdG9wLWNvbG9yPSIjYTg1NWY3IiBzdG9wLW9wYWNpdHk9IjAuMTgiLz4KICAgICAgPHN0b3Agb2Zmc2V0PSIxIiBzdG9wLWNvbG9yPSIjYTg1NWY3IiBzdG9wLW9wYWNpdHk9IjAiLz4KICAgIDwvbGluZWFyR3JhZGllbnQ+CiAgPC9kZWZzPgogIDxyZWN0IHdpZHRoPSIxMjAwIiBoZWlnaHQ9IjMyMCIgcng9IjI2IiBmaWxsPSIjMGEwZDEyIi8+CiAgPHJlY3Qgd2lkdGg9IjEyMDAiIGhlaWdodD0iMzIwIiByeD0iMjYiIGZpbGw9InVybCgjZWRnZSkiLz4KICA8cmVjdCB4PSIwLjUiIHk9IjAuNSIgd2lkdGg9IjExOTkiIGhlaWdodD0iMzE5IiByeD0iMjUuNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjMWMyMTI5IiBzdHJva2Utd2lkdGg9IjEiLz4KCiAgPGcgaWQ9InRpdGxlLWJsb2NrIiB0cmFuc2Zvcm09InRyYW5zbGF0ZSg1NiA2NCkiPgogICAgPHJlY3QgeD0iMCIgeT0iLTI4IiB3aWR0aD0iMTAiIGhlaWdodD0iMTAiIHJ4PSIyIiBmaWxsPSIjYTg1NWY3Ii8+CiAgICA8dGV4dCB4PSIyMCIgeT0iLTIwIiBmb250LWZhbWlseT0idWktbW9ub3NwYWNlLCBTRk1vbm8tUmVndWxhciwgTWVubG8sIG1vbm9zcGFjZSIgZm9udC1zaXplPSIxMiIgZmlsbD0iI2E4NTVmNyI+U0VDVVJJVFkgU0NBTk5FUiDCtyBSRUFMIERBVEEsIE5PIEZBQlJJQ0FUSU9OPC90ZXh0PgogICAgPHRleHQgeD0iMCIgeT0iMjYiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjQwIiBmb250LXdlaWdodD0iODAwIiBmaWxsPSIjZmZmZmZmIj5TeWZ0IFNCT00gR2VuZXJhdG9yPC90ZXh0PgogICAgPHRleHQgeD0iMCIgeT0iNjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjE2IiBmaWxsPSIjYzlkMWQ5Ij5SZWFsIEN5Y2xvbmVEWCAvIFNQRFggYmlsbCBvZiBtYXRlcmlhbHMsIG5vdCBhIGd1ZXNzPC90ZXh0PgogICAgPGcgdHJhbnNmb3JtPSJ0cmFuc2xhdGUoMCAxMDApIj4KICAgICAgCiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgwIDApIj4KICAgICAgPHRleHQgeD0iMCIgeT0iMCIgZm9udC1mYW1pbHk9Ii1hcHBsZS1zeXN0ZW0sIEJsaW5rTWFjU3lzdGVtRm9udCwgU2Vnb2UgVUksIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMjgiIGZvbnQtd2VpZ2h0PSI3MDAiIGZpbGw9IiNmZmZmZmYiPjEyMTwvdGV4dD4KICAgICAgPHRleHQgeD0iMCIgeT0iMjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjEyIiBmaWxsPSIjOGI5NDllIj5QYWNrYWdlcyBmb3VuZDwvdGV4dD4KICAgIDwvZz4KICAgIDxnIHRyYW5zZm9ybT0idHJhbnNsYXRlKDE1MCAwKSI+CiAgICAgIDx0ZXh0IHg9IjAiIHk9IjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjI4IiBmb250LXdlaWdodD0iNzAwIiBmaWxsPSIjZmZmZmZmIj4yPC90ZXh0PgogICAgICA8dGV4dCB4PSIwIiB5PSIyMCIgZm9udC1mYW1pbHk9Ii1hcHBsZS1zeXN0ZW0sIEJsaW5rTWFjU3lzdGVtRm9udCwgU2Vnb2UgVUksIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTIiIGZpbGw9IiM4Yjk0OWUiPkZvcm1hdHM8L3RleHQ+CiAgICA8L2c+CiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgzMDAgMCkiPgogICAgICA8dGV4dCB4PSIwIiB5PSIwIiBmb250LWZhbWlseT0iLWFwcGxlLXN5c3RlbSwgQmxpbmtNYWNTeXN0ZW1Gb250LCBTZWdvZSBVSSwgc2Fucy1zZXJpZiIgZm9udC1zaXplPSIyOCIgZm9udC13ZWlnaHQ9IjcwMCIgZmlsbD0iI2ZmZmZmZiI+MzwvdGV4dD4KICAgICAgPHRleHQgeD0iMCIgeT0iMjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjEyIiBmaWxsPSIjOGI5NDllIj5QYWNrYWdlIHR5cGVzPC90ZXh0PgogICAgPC9nPgogICAgPC9nPgogIDwvZz4KCiAgPGcgaWQ9InByb2plY3QtcHJvb2YiIHRyYW5zZm9ybT0idHJhbnNsYXRlKDcwMCA3NikiPgogICAgPHJlY3QgeD0iLTI0IiB5PSItNDAiIHdpZHRoPSI0NzAiIGhlaWdodD0iMjIwIiByeD0iMTQiIGZpbGw9IiMwZDExMTciIHN0cm9rZT0iIzFjMjEyOSIgc3Ryb2tlLXdpZHRoPSIxIi8+CiAgICA8dGV4dCB4PSIwIiB5PSItMTQiIGZvbnQtZmFtaWx5PSJ1aS1tb25vc3BhY2UsIFNGTW9uby1SZWd1bGFyLCBNZW5sbywgbW9ub3NwYWNlIiBmb250LXNpemU9IjExIiBmaWxsPSIjOGI5NDllIj4kIGFwaWZ5IGNhbGwgc3lmdC1zYm9tLWdlbmVyYXRvcjwvdGV4dD4KICAgIDxnIHRyYW5zZm9ybT0idHJhbnNsYXRlKDAgMTYpIj4KICAgICAgCiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgwIDApIj4KICAgICAgPHJlY3QgeD0iMCIgeT0iMCIgd2lkdGg9IjEwIiBoZWlnaHQ9IjEwIiByeD0iMiIgZmlsbD0iI2E4NTVmNyIvPgogICAgICA8dGV4dCB4PSIxOCIgeT0iOSIgZm9udC1mYW1pbHk9InVpLW1vbm9zcGFjZSwgU0ZNb25vLVJlZ3VsYXIsIE1lbmxvLCBtb25vc3BhY2UiIGZvbnQtc2l6ZT0iMTIiIGZpbGw9IiNjOWQxZDkiPmRlYiAgODcgcGFja2FnZXM8L3RleHQ+CiAgICA8L2c+CiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgwIDI2KSI+CiAgICAgIDxyZWN0IHg9IjAiIHk9IjAiIHdpZHRoPSIxMCIgaGVpZ2h0PSIxMCIgcng9IjIiIGZpbGw9IiNhODU1ZjciLz4KICAgICAgPHRleHQgeD0iMTgiIHk9IjkiIGZvbnQtZmFtaWx5PSJ1aS1tb25vc3BhY2UsIFNGTW9uby1SZWd1bGFyLCBNZW5sbywgbW9ub3NwYWNlIiBmb250LXNpemU9IjEyIiBmaWxsPSIjYzlkMWQ5Ij5weXRob24gIDE5IHBhY2thZ2VzPC90ZXh0PgogICAgPC9nPgogICAgPGcgdHJhbnNmb3JtPSJ0cmFuc2xhdGUoMCA1MikiPgogICAgICA8cmVjdCB4PSIwIiB5PSIwIiB3aWR0aD0iMTAiIGhlaWdodD0iMTAiIHJ4PSIyIiBmaWxsPSIjYTg1NWY3Ii8+CiAgICAgIDx0ZXh0IHg9IjE4IiB5PSI5IiBmb250LWZhbWlseT0idWktbW9ub3NwYWNlLCBTRk1vbm8tUmVndWxhciwgTWVubG8sIG1vbm9zcGFjZSIgZm9udC1zaXplPSIxMiIgZmlsbD0iI2M5ZDFkOSI+YmluYXJ5ICAxNSBwYWNrYWdlczwvdGV4dD4KICAgIDwvZz4KICAgIDxnIHRyYW5zZm9ybT0idHJhbnNsYXRlKDAgNzgpIj4KICAgICAgPHJlY3QgeD0iMCIgeT0iMCIgd2lkdGg9IjEwIiBoZWlnaHQ9IjEwIiByeD0iMiIgZmlsbD0iIzUxY2Y2NiIvPgogICAgICA8dGV4dCB4PSIxOCIgeT0iOSIgZm9udC1mYW1pbHk9InVpLW1vbm9zcGFjZSwgU0ZNb25vLVJlZ3VsYXIsIE1lbmxvLCBtb25vc3BhY2UiIGZvbnQtc2l6ZT0iMTIiIGZpbGw9IiNjOWQxZDkiPlNCT00gc2F2ZWQgdG8ga2V5LXZhbHVlIHN0b3JlIMK3IHNib208L3RleHQ+CiAgICA8L2c+CiAgICA8L2c+CiAgPC9nPgo8L3N2Zz4=" width="100%" alt="syft-sbom-generator hero banner">
</p>

<p align="center">
  <a href="https://github.com/anchore/syft"><img src="https://img.shields.io/badge/powered%20by-Syft-A855F7?style=for-the-badge" alt="Powered by Syft"></a>
  <img src="https://img.shields.io/badge/License-Apache--2.0-555555?style=for-the-badge" alt="Apache 2.0">
  <img src="https://img.shields.io/badge/Formats-CycloneDX%20%C2%B7%20SPDX-F86606?style=for-the-badge" alt="CycloneDX and SPDX">
</p>

<p align="center">
  <a href="#the-problem-this-solves">Why it exists</a> &bull;
  <a href="#use-cases">Use cases</a> &bull;
  <a href="#input">Input</a> &bull;
  <a href="#output">Output</a> &bull;
  <a href="#pricing">Pricing</a>
</p>

## Syft SBOM Generator

**A real, standards-compliant Software Bill of Materials for any container image or public repo — CycloneDX or SPDX, ready for compliance tooling.**

> **Verified live** against `python:3.9-slim`: 121 real packages identified (87 deb, 19 python, 15 binary), each with exact installed version — cross-checked against the image's own package list, not estimated.

### The problem this solves

SBOMs are increasingly a compliance requirement (US Executive Order 14028, EU Cyber Resilience Act), and "what's actually inside this container" is a question most teams can't answer without tooling. This Actor identifies every package [Syft](https://github.com/anchore/syft) can positively detect — pip, npm, Go modules, Maven/Gradle, RubyGems, OS packages, and more — with exact version and declared license, not a guess.

### Use cases

- **Regulatory compliance** — generate a CycloneDX/SPDX document to satisfy EO 14028 or EU Cyber Resilience Act SBOM requirements.
- **Vendor risk assessment** — request an SBOM from a third-party vendor, or generate one yourself from their public image, before approving procurement.
- **License compliance audit** — identify GPL/AGPL-licensed packages that may conflict with your product's licensing before shipping.
- **Vulnerability response prep** — keep a current SBOM on hand so that when a new CVE drops, you can immediately check exposure without re-scanning from scratch.
- **M\&A technical due diligence** — inventory exactly what's running inside a target company's production containers.
- **Feed a vulnerability matcher** — pipe the generated SBOM into [Grype Vulnerability Matcher](https://apify.com/ayeeyee/grype-vulnerability-matcher) for a full CVE report.

### Input

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `target` | string | yes | Container image (`nginx:1.19`) or git repo URL |
| `scanType` | string | no | `image` or `repo` — auto-detected if left blank |
| `outputFormat` | string | no | `cyclonedx-json` (default), `spdx-json`, or `syft-json` |

```json
{ "target": "python:3.9-slim", "outputFormat": "cyclonedx-json" }
```

### Output

One row per real package found (name, version, type, language, PURL, license), plus one `sbom_summary` row with totals by package type. The full SBOM document is saved to the run's key-value store under the key `sbom`.

One real package from a live scan:

```json
{
  "findingType": "package",
  "target": "python:3.9-slim",
  "name": "Simple Launcher",
  "version": "1.1.0.14",
  "packageType": "binary",
  "language": "",
  "purl": "",
  "licenses": [],
  "locationPath": "/usr/local/lib/python3.9/site-packages/pip/_vendor/distlib/t32.exe",
  "scannedAt": "2026-08-01T16:35:21.630682+00:00"
}
```

### Frequently asked questions

**Which package ecosystems does it detect?**
Whatever Syft itself supports — OS packages (deb/rpm/apk), Python, npm, Go modules, Java (Maven/Gradle), RubyGems, and several more, all in a single pass over the target.

**Where do I get the full SBOM document, not just the row-per-package view?**
The complete CycloneDX or SPDX JSON document is saved to the run's key-value store under the key `sbom` — the dataset gives you a searchable per-package view, the key-value store gives you the standards-compliant document to hand to a compliance tool.

**Can I feed this straight into a vulnerability scanner?**
Yes — that's a common pairing. Generate the SBOM here, then run [Grype Vulnerability Matcher](https://apify.com/ayeeyee/grype-vulnerability-matcher) against the same target for a CVE report matched against the exact package list.

**What if a package has no declared license?**
It's returned with an empty `licenses` array rather than guessed — Syft only reports what's actually declared in the package metadata.

### Limitations

- Only public container images and public git repos are supported.
- License detection reflects what the package itself declares — undeclared or non-standard license files may not be picked up.
- Binary packages (like the example above) often have empty `language`/`purl` fields since they don't carry ecosystem package-manager metadata — that's expected, not missing data.

### Start generating

Give it a container image or a public repo URL and pick CycloneDX or SPDX — the format your compliance tooling expects.

### Pricing

Pay per completed scan (Pay-Per-Event) — **$0.49 per SBOM**, charged once the SBOM is generated regardless of package count.

### Related Actors

Part of a five-Actor security scanning catalog: [Trivy Security Scanner](https://apify.com/ayeeyee/trivy-security-scanner), [Gitleaks Secret Scanner](https://apify.com/ayeeyee/gitleaks-secret-scanner), [Grype Vulnerability Matcher](https://apify.com/ayeeyee/grype-vulnerability-matcher) (feed this SBOM straight into it), [OSV-Scanner Vulnerability Checker](https://apify.com/ayeeyee/osv-scanner-vulnerability-checker).

# Actor input Schema

## `target` (type: `string`):

Container image reference (e.g. "nginx:1.19") or git repository URL to generate a Software Bill of Materials for.

## `scanType` (type: `string`):

image or repo. Auto-detected from the target if left empty.

## `outputFormat` (type: `string`):

Standard format for the full SBOM document saved to the key-value store (in addition to per-package dataset rows).

## Actor input object example

```json
{
  "target": "python:3.9-slim",
  "scanType": "",
  "outputFormat": "cyclonedx-json"
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "target": "python:3.9-slim"
};

// Run the Actor and wait for it to finish
const run = await client.actor("ayeeyee/syft-sbom-generator").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "target": "python:3.9-slim" }

# Run the Actor and wait for it to finish
run = client.actor("ayeeyee/syft-sbom-generator").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "target": "python:3.9-slim"
}' |
apify call ayeeyee/syft-sbom-generator --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=ayeeyee/syft-sbom-generator",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/acts/PZg4AbdaUCKJQZTxR/builds/YSVgzCQdurKJz44P9/openapi.json
