Seismograph

What’s gaining stars on GitHub right now

anchore/syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

SecurityGo#containers#docker#go#golang#static-analysis
1.2 Steady Magnitude out of 10. Star growth looks organic. Data as of September 19, 2026.
Open on Seismograph Open on GitHub

About the project

A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images, filesystems, and archives. Supports many packaging ecosystems and output formats (CycloneDX, SPDX).

Useful for

README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.

Why it’s trending

Stars per day

01020June 22, 2026September 19, 2026

Bars are daily stars, the line is the usual pace. Red marks spike days.

Numbers

Total stars
9,581
Stars in a day
5
Forks
962
Issues and pull requests
5,272
Watchers
72
Language
Go
License
Apache-2.0
Latest release
v1.52.0 · September 17, 2026
Created
May 7, 2020
Last push
September 18, 2026

Star trust

Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.

These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.

Spotted in

Share

README badge

Paste it into your README — the badge shows the current magnitude and links to this page.

Seismograph: 1.2
[![Seismograph](https://gitnova.dev/badge/anchore/syft.svg?lang=en)](https://gitnova.dev/en/r/anchore/syft)

Similar projects

  1. 9.3
    cloudflare/security-audit-skill

    A coding-agent skill that turns the agent into a security auditor, running a multi-phase code audit with independently verified, machine-readable findings.

    BreakoutSecurityJavaScript+1,742 stars in a day

  2. 7.1
    arvindear/wp2shell-PoC

    Proof-of-concept for the wp2shell vulnerability chain in WordPress Core (CVE-2026-63030 and CVE-2026-60137) that gives an unauthenticated attacker RCE. A tool for testing and exploitation in controlled environments and…

    Early signalSecurityPython+291 stars in a day

  3. 5.1
    yynxxxxx/gpt_sub_analysis

    A guide to analyzing the ChatGPT iOS subscription flow: it describes intercepting the buyProduct request via Reqable and SSL Kill Switch 3 and rewriting the offerName and salableAdamId fields to obtain the Pro 20x…

    Early signalSecurity+42 stars in a day

  4. 3.8
    BennyThink/NFCX

    Cross-platform GUI desktop app for NFC card work: reader discovery, MIFARE Classic reads, dumps, key management, and key recovery. For cards you own or are authorized to test.

    Early signalSecurityGo+19 stars in a day

  5. 3.7
    NationalSecurityAgency/ghidra

    A software reverse engineering framework from the NSA: disassembly, decompilation, graphing and scripting for analyzing compiled code on Windows, macOS and Linux.

    PeakingSecurityJava+115 stars in a day

  6. 3.5
    bl4ckarch/go-responder

    A Go port of Responder: poisons LLMNR, NBT-NS and mDNS, runs rogue servers (SMB, HTTP, LDAP, etc.) and captures NTLM hashes and cleartext credentials.

    Early signalSecurityGo+10 stars in a day