Skip to main content

Source code scanner to analyze code bases and compare them with source code artifacts archived by Software Heritage.

Getting Started

Installation

To install the Software Heritage scanner, run:

pip install swh-scanner

Note that it will install swh-scanner and its dependencies in the current virtualenv (if any). If you just want to install the scanner as a standalone tool, you may want to use an installation tool like pipx or uv:

$ uv tool install --with swh-scanner swh-core

or

$ pipx install --include-deps swh-scanner

Registering to the Software Heritage Archive

To efficiently query the Software Heritage Archive, you need to create an account. This is not strictly necessary, but the rate limit imposed on anonymous users will likely result in very slow operation.

First, visit https://archive.softwareheritage.org/oidc/login/ and create a new user by clicking on Register.

Configuring your scan

The scanner will guide you through your initial configuration through the setup command, including setting up your authentication token:

swh scanner setup

Running a Scan

To scan your local file in PROJECT_PATH, use:

swh scanner scan PROJECT_PATH

This will find your local files, query the archive, and provide you with a graphical user interface to browse the result.

Note that the scan command has a --provenance flag that retrieves information about where the files known to the archive might come from. This option is experimental and you need to get in touch with the Software Heritage team to be granted permission to the necessary APIs. Alternatively, there is a button in the dashboard that will query the provenance for a given selected file or directory. This is also experimental and gated to privileged users.

Further Configuration

The scanner will add up configuration options from three places, in order of precedence:

  • The command line

  • The project config file

  • The global config file

You can view the command line options by invoking swh scanner scan --help.

The scanner will look for a swh.scanner.project.yml file inside the directory being scanned, or at the path given to --project-config-file.

The global configuration resides in the swh > scanner section of the shared YAML configuration file used by all Software Heritage tools, located by default at ~/.config/swh/global.yml.

The configuration file location is subject to the XDG Base Directory specification as well as explicitly overridden on the command line via the -C/--config-file flag.

The following sub-sections and fields can be used within the swh > scanner stanza:

  • disable_global_patterns (default: false): whether to disable the global exclusion patterns, which refer to very common patterns of files to exclude from the scan. Only use this if you’re finding that some files are being ignored that you would want to scan, though very unlikely.

  • disable_vcs_patterns (default: false): whether to stop using the ignore mechanisms from version control systems (.gitignore, .hgignore, .svnignore). Note that this ignore mechanism only works in the first place if the VCS is available in your PATH (Git, Mercurial or SVN).

  • exclude: (default: []): a list of glob patterns of paths to exclude from the scan, to use on top of all other exclusion patterns.

  • exclude_templates: (default: []): a list of names of exclusion templates (as listed in the scanner’s help) to use on top of all other exclusion patterns. This is useful if you want to exclude all common Python cache files for example.

Here is an example:

scanner:
  disable_global_patterns: false
  disable_vcs_patterns: false
  exclude: ["ignored*", "someotherpattern"]
  exclude_templates: ["Python", "Go", "Rust", "Node"]

Metadata

Release files for swh.scanner 0.8.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for swh.scanner 0.8.3
File Size Uploaded
swh_scanner-0.8.3.tar.gz 206.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for swh.scanner 0.8.3
File Interpreter ABI Platform
swh.scanner-0.8.3-py3-none-any.whl Python 3 none any Details

Total release size: 467.8 kB

Release files / swh_scanner-0.8.3.tar.gz

Download URL swh_scanner-0.8.3.tar.gz
Size 206.6 kB
Tags Source
SHA-256 checksum
How to use checksums
d0b09abaa243207203d0766fb4f2b7b6cb47ed7d4c316f2b95876bfbb5c36e44
BLAKE2b-256 checksum
How to use checksums
738d3946090b346a0cf41abb97bd5aed3de223206fbbdb25f48319a5e2a93c11
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.11.9

Release files / swh.scanner-0.8.3-py3-none-any.whl

Download URL swh.scanner-0.8.3-py3-none-any.whl
Size 261.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d13abac078d995e6dd15c3ff848180066b111bc678b932f67e1c997a1f4ca65a
BLAKE2b-256 checksum
How to use checksums
5eebcf6b28fc7f07758c2c7c053a0ee664021c3a67020e0ad6bcecc2947e6bf8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.11.9

Release history Release notifications | RSS feed

This release

0.8.3 This release

2 release files

0.8.2

2 release files

0.8.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page