Problem
scanoss -C (component_scan in src/purl_scan.c) serves /scan/components, the call batchScanner uses to fetch component details for a scan. Its output has no KB version:
{"results": [{"url_hash": "...", "component": {...}}, ...]}
Because of that, batchScanner cannot fill server.knowledge_base in its report (scanoss/batchScanner#7). Clients such as Earnie need the KB version to reuse cached OSS matches between scans. Today they work around it with a dummy POST /scan/direct, because only that path emits server.kb_version.
-P (/scan/raw) and the snippet scan don't emit it either.
Proposal
Add a server block to the -C output, after results:
{
"results": [ ... ],
"server": {
"version": "6.0.0-crc64",
"kb_version": {"monthly": "26.09", "daily": "26.09.27"}
}
}
- The data is already there:
initialize_ldb_tables() calls kb_version_get() before -C runs, so the global kb_version is loaded. version is SCANOSS_VERSION.
- Emit only
version and kb_version. Do not add hostname, flags or elapsed as print_server_stats() does. batchScanner calls -C in several batches, and every batch should return the same block.
- Keep the current fallback. When
/var/lib/ldb/<db>/version.json is missing, kb_version is the string "N/A". Consumers must accept both the object and that string.
- Respect
quiet in the same way results does.
The change is additive. Existing consumers read only results.
Acceptance
Follow-up
- batchScanner maps this block to its report schema:
api_version, knowledge_base.monthly_version and knowledge_base.daily_version (scanoss/batchScanner#7).
- Check that the HTTP layer serving
/scan/components passes the server key through unchanged.
Problem
scanoss -C(component_scaninsrc/purl_scan.c) serves/scan/components, the call batchScanner uses to fetch component details for a scan. Its output has no KB version:{"results": [{"url_hash": "...", "component": {...}}, ...]}Because of that, batchScanner cannot fill
server.knowledge_basein its report (scanoss/batchScanner#7). Clients such as Earnie need the KB version to reuse cached OSS matches between scans. Today they work around it with a dummyPOST /scan/direct, because only that path emitsserver.kb_version.-P(/scan/raw) and the snippet scan don't emit it either.Proposal
Add a
serverblock to the-Coutput, afterresults:{ "results": [ ... ], "server": { "version": "6.0.0-crc64", "kb_version": {"monthly": "26.09", "daily": "26.09.27"} } }initialize_ldb_tables()callskb_version_get()before-Cruns, so the globalkb_versionis loaded.versionisSCANOSS_VERSION.versionandkb_version. Do not addhostname,flagsorelapsedasprint_server_stats()does. batchScanner calls-Cin several batches, and every batch should return the same block./var/lib/ldb/<db>/version.jsonis missing,kb_versionis the string"N/A". Consumers must accept both the object and that string.quietin the same wayresultsdoes.The change is additive. Existing consumers read only
results.Acceptance
scanoss -C <hash>[,<hash>...]returns valid JSON withresultsandserver.{version,kb_version}.kb_versionmatches the contents ofversion.jsonfor the loaded DB, or is"N/A"when that file is missing.Follow-up
api_version,knowledge_base.monthly_versionandknowledge_base.daily_version(scanoss/batchScanner#7)./scan/componentspasses theserverkey through unchanged.