Skip to content
LatchkeyLatchkey home

syft -o: Output Formats and Multiple Files

syft -o selects one or more SBOM output formats and can write each to its own file in a single run.

syft supports many SBOM encodings. The -o flag chooses them, and because it is repeatable you can emit, say, a human table to the log and a CycloneDX JSON to disk at once.

What it does

syft -o <format> picks an output encoding; appending =<file> writes that format to a file instead of stdout. The flag is repeatable, so one scan can produce several formats. Format names include syft-json, table, cyclonedx-json, cyclonedx-xml, spdx-json, and spdx-tag-value.

Common usage

Terminal
syft myorg/app:ci -o table
# two formats at once: table to the log, CycloneDX to a file
syft myorg/app:ci -o table -o cyclonedx-json=sbom.cdx.json
syft myorg/app:ci -o spdx-json=sbom.spdx.json -o syft-json=sbom.syft.json

Options

FormatWhat it is
syft-jsonSyft native JSON, the richest representation
tableHuman-readable table for logs
cyclonedx-json / -xmlCycloneDX SBOM in JSON or XML
spdx-jsonSPDX SBOM in JSON
spdx-tag-valueSPDX in the tag:value text format
<fmt>=<file>Write that format to a file

In CI

Emit a table to stdout for quick log review and a machine format (cyclonedx-json or spdx-json) to a file for artifacts and attestation, all in one syft invocation. Prefer syft-json as the internal artifact since grype reads it losslessly.

Common errors in CI

"unknown output format" means a misspelled name; the correct spellings use hyphens (cyclonedx-json, not cyclonedx_json). Writing two formats to stdout (both without =file) interleaves them into unusable output; give at least all but one an =file target.

Frequently asked questions

syft -o: Output Formats and Multiple Files?
syft supports many SBOM encodings. The -o flag chooses them, and because it is repeatable you can emit, say, a human table to the log and a CycloneDX JSON to disk at once.
What it does?
syft -o <format> picks an output encoding; appending =<file> writes that format to a file instead of stdout. The flag is repeatable, so one scan can produce several formats. Format names include syft-json, table, cyclonedx-json, cyclonedx-xml, spdx-json, and spdx-tag-value.
In CI?
Emit a table to stdout for quick log review and a machine format (cyclonedx-json or spdx-json) to a file for artifacts and attestation, all in one syft invocation. Prefer syft-json as the internal artifact since grype reads it losslessly.
Common errors in CI?
"unknown output format" means a misspelled name; the correct spellings use hyphens (cyclonedx-json, not cyclonedx_json). Writing two formats to stdout (both without =file) interleaves them into unusable output; give at least all but one an =file target.

Related guides

References

Run this faster and cheaper on Latchkey managed runners - self-healing included. Start free → 30-day trial · No credit card