Goal
A release does not change after you ship it, but the list of known vulnerabilities in its components does. New advisories come out every day. This recipe takes the inventory you stored at release time, refreshes its vulnerability and licence data every week, and reports the advisories that are new since the last run.When to use it
- You ship releases that customers run for months or years, and you must know when a new vulnerability affects one of them.
- You keep the inventory or SBOM from each release (for example, from the release SBOM recipe).
- The job that runs the refresh may not have the source code.
enrichdoes not need it.
How enrich works
scanoss-cli enrich reads an existing inventory or SBOM, looks up each component by its PURL
through the SCANOSS API, and writes the file again with fresh data. It does not fingerprint or
scan anything, so it is quick, and you can run it as often as you like on the same file.
Choose the layers with
--include: vulns, licenses, crypto, and geo. Use -f, --format
to write a different format in the same pass.
Prerequisites
- scanoss-cli,
jq, andSCANOSS_API_KEY(see Recipes) - A stored inventory, for example
inventory-2.4.0.jsonfrom a release - A scheduler: your CI system’s scheduled pipelines, or
cron
The script
Save this asci/scanoss-refresh.sh.
What each step does
- Refresh.
enrichreplaces the vulnerability and licence data of every component with the current data. It does not change the components or their evidence. If a lookup fails,enrichstill writes a file and exits0, but prints a warning on stderr:Enrichment incompletewhen a whole layer failed, orlayer returned no data for some componentswhen part of it failed. The script treats both as a failure, so you never compare against partial data. - Compare.
jqreads the previous file with--slurpfileand lists every advisory ID in the new file that the previous file did not have. - Gate. Only new advisories at or above
FAIL_ON_SEVERITYfail the job. Known advisories, which you have already seen, do not fail it again.
What the output means
How it fails the pipeline
Schedule it
Any scheduler works. Withcron, on a machine that has the files and the key:
Refresh an SBOM instead of the raw inventory
enrich also reads CycloneDX and SPDX files, and the comparison above works on raw files. For a
CycloneDX SBOM, refresh it in place:
enrich skips the vulns layer for SPDX output and prints a
notice. To get vulnerability data for a release you only have as SPDX, write CycloneDX in the same
pass:
enrich cannot add the deps layer, because declared dependencies come from manifest files in
the source tree. Include deps when you first scan the release, as the
release SBOM recipe does.