Skip to content

feat(scan): surface match confidence in results - #96

Merged
mscasso-scanoss merged 1 commit into
mainfrom
feat/scan-match-confidence
Sep 28, 2026
Merged

mscasso-scanoss merged 1 commit into
mainfrom
feat/scan-match-confidence

Conversation

@mscasso-scanoss

Copy link
Copy Markdown
Contributor

What

Bumps github.com/scanoss/scanoss.api-sdk v0.8.0 → v0.26.0, which adds MatchResult.Confidence (LOW/MEDIUM/HIGH), and carries the grade through to scan output:

  • pkg/sbom/inventory.go — FileEvidence gains Confidence string json:"confidence,omitempty".
  • pkg/sbom/scansource/scansource.go — filesByURLHash maps Confidence: string(m.Confidence).

Why

batchScanner v0.0.7 grades every match with a confidence; the API (scanoss.api ≥ v0.26.0) now declares it on MatchResult. Before this change the CLI decoded matches via scanossapi.MatchResult, which lacked the field, so confidence was silently discarded and never reached the output.

Verification

  • go build ./... ✅ against the published scanoss.api-sdk@v0.26.0 (no replace).
  • End-to-end: scanned against a live API and the output carries "confidence": "LOW" per evidence entry.

Depends on scanoss.api#202 (merged, released as v0.26.0).

🤖 Generated with Claude Code

Bump scanoss.api-sdk to v0.26.0, which adds MatchResult.Confidence
(LOW/MEDIUM/HIGH), and carry it through to the output: add Confidence to
sbom.FileEvidence and map it in filesByURLHash. Previously the field was
silently dropped because the SDK type did not declare it.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@mscasso-scanoss
mscasso-scanoss merged commit cc4354f into main Sep 28, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant