Enrich an existing inventory
enrich decorates an existing inventory or SBOM with purl-keyed layers through the SCANOSS API.
It needs no source tree, and it doesn’t fingerprint or re-scan anything. Because it works only from
PURLs, you can re-run it on the same file, weekly for example, to refresh the layers.
enrich accepts a SCANOSS raw inventory, a CycloneDX document, or an SPDX document, all in JSON,
and detects which one it has from the content. The layers you can pass to --include are vulns,
licenses, crypto, and geo. deps is not an enrich layer. Dependency analysis needs
manifests or a source tree, so --include deps returns an error here.
By default the output keeps the input’s format, so raw stays raw, CycloneDX stays CycloneDX, and
SPDX stays SPDX. Pass -f, --format to convert in the same pass. If the output format can’t
represent a layer, enrich skips that layer up front and prints a notice, following the same rules
as scan. spdx skips vulns, crypto, and geo, and cyclonedx skips crypto and geo. A
failed service doesn’t stop enrichment. enrich logs the failure, skips that service, and still
writes a partial result.
enrich takes --include and -f, --format (raw, spdx, or cyclonedx), plus the
API flags (--api-url,
--api-key, --proxy, --ca-cert, --ignore-cert-errors, -o, --output).
Dependencies
dependencies has two modes. Local mode parses the manifests under a path. API mode looks up one
component by PURL:
dependencies also takes the API flags.
Decoration lookups
Each decoration command queries the SCANOSS v3 API about one or more components. Each one is a parent command with one subcommand per operation, and running a command with no subcommand uses its default operation. The input is a list of PURLs, which you give by repeating--purl or by passing
--input. The CLI splits the list into chunks and queries them concurrently.
All decoration commands share these flags: --purl (repeatable), --requirement (version or
range), --input (a PURL file, either newline-delimited purl[,requirement] or JSON
{"components":[...]}), --chunk-size (10), and -t, --workers (5). They also take the API flags.
components search, versions and releases take their own flags instead of a PURL list:
When a component exists but has no release notes for the resolved version,
components releases
prints a “no release notes available” notice on stderr, still emits the JSON, and exits 0.