Skip to main content

Enrich an existing inventory

enrich decorates an existing inventory or SBOM with purl-keyed layers through the SCANOSS API. It needs no source tree, and it doesn’t fingerprint or re-scan anything. Because it works only from PURLs, you can re-run it on the same file, weekly for example, to refresh the layers.
enrich accepts a SCANOSS raw inventory, a CycloneDX document, or an SPDX document, all in JSON, and detects which one it has from the content. The layers you can pass to --include are vulns, licenses, crypto, and geo. deps is not an enrich layer. Dependency analysis needs manifests or a source tree, so --include deps returns an error here. By default the output keeps the input’s format, so raw stays raw, CycloneDX stays CycloneDX, and SPDX stays SPDX. Pass -f, --format to convert in the same pass. If the output format can’t represent a layer, enrich skips that layer up front and prints a notice, following the same rules as scan. spdx skips vulns, crypto, and geo, and cyclonedx skips crypto and geo. A failed service doesn’t stop enrichment. enrich logs the failure, skips that service, and still writes a partial result. enrich takes --include and -f, --format (raw, spdx, or cyclonedx), plus the API flags (--api-url, --api-key, --proxy, --ca-cert, --ignore-cert-errors, -o, --output).

Dependencies

dependencies has two modes. Local mode parses the manifests under a path. API mode looks up one component by PURL:
dependencies also takes the API flags.

Decoration lookups

Each decoration command queries the SCANOSS v3 API about one or more components. Each one is a parent command with one subcommand per operation, and running a command with no subcommand uses its default operation. The input is a list of PURLs, which you give by repeating --purl or by passing --input. The CLI splits the list into chunks and queries them concurrently. All decoration commands share these flags: --purl (repeatable), --requirement (version or range), --input (a PURL file, either newline-delimited purl[,requirement] or JSON {"components":[...]}), --chunk-size (10), and -t, --workers (5). They also take the API flags.
components search, versions and releases take their own flags instead of a PURL list:
When a component exists but has no release notes for the resolved version, components releases prints a “no release notes available” notice on stderr, still emits the JSON, and exits 0.