syft · Issues· 647 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #5305
CHANGELOG.md has wrong file permissions in the released .tar.gz
bugUpdated Sep 18, 2026 - #5299
github-actions cataloger emits an invalid PURL for docker:// use statements
buggood-first-issueUpdated Sep 17, 2026 - #1229
Exclude/remove base image packages from final SBOM
enhancementneeds-proposalUpdated Sep 17, 2026 - #1173
Analyze with Non-Daemon podman
enhancementUpdated Sep 17, 2026 - #5269
java-pom-cataloger reports dependencies from profiles that cannot be active
Updated Sep 17, 2026 - #4563
Different results on Windows and macOS/Linux while scanning OCI images
bugUpdated Sep 15, 2026 - #5193
Support for concurrent package registry requests when using `--enrich`
enhancementUpdated Sep 14, 2026 - #5129
Add catalogers for Ansible collections and roles
needs-proposalUpdated Sep 14, 2026 - #2828
Binary copied to image omitted from SBOM
enhancementgood-first-issuebinary-analysisUpdated Sep 11, 2026 - #5266
Reconsider dependency on archived fork https://github.com/anchore/go-version
enhancementUpdated Sep 10, 2026 - #5214
exclude-binary-overlap-by-ownership suppresses vendored libraries owned by unrelated RPMs
bugUpdated Sep 10, 2026 - #5149
Adding GitHub attestations
enhancementreleaseUpdated Sep 9, 2026 - #4209
SBOM for Github Actions workflow files
enhancementUpdated Sep 7, 2026 - #3071
Dependency graph of BOMs generated with Syft is incomplete due to missing root node
bugUpdated Sep 3, 2026 - #4747
Syft does not use parent pom.xml for license detection if MANIFEST.MF contains Bundle-License
buggood-first-issueUpdated Sep 3, 2026