Skip to content

1.1.2

Choose a tag to compare

@oscarvalenzuelab oscarvalenzuelab released this 20 Aug 21:25
· 70 commits to main since this release

src2id v1.1.2 - First Public Release

What is src2id?

src2id (Source Code to ID) identifies package coordinates (name, version, license, PURL) from source code directories. It helps you understand "what is this code?" when dealing with unknown dependencies or
analyzing open source components.

Key Features

  • Multiple identification strategies: Hash search, web search (GitHub/Google), SCANOSS fingerprinting, and optional Software Heritage archive
  • Subcomponent detection: Identifies multiple packages within monorepos and complex projects
  • License detection: Integrated with oslili for accurate license identification
  • Smart ordering: Optimized strategy order minimizes API calls (30x faster than single-strategy approaches)
  • Package URLs (PURLs): Generates standard package identifiers
  • Confidence scoring: Multi-factor scoring for match reliability
  • Persistent caching: 24-hour cache to avoid API rate limits

Installation

git clone https://github.com/oscarvalenzuelab/semantic-copycat-src2id.git
cd semantic-copycat-src2id
pip install -e .

Quick Start

Basic package identification

src2id /path/to/unknown/code

With subcomponent detection for monorepos

src2id /path/to/monorepo --detect-subcomponents

Include Software Heritage archive search

src2id /path/to/code --use-swh

JSON output for automation

src2id /path/to/code --output-format json

Example Output

src2id v1.1.2
Analyzing: test_data/darktable

Local Source Analysis
✓ Licenses detected: GPL-3.0, BSD-3-Clause, MIT and 4 more
Confidence: 94.1%

Name Confidence Method PURL
darktable 0.80 fuzzy pkg:generic/darktable

License

GNU Affero General Public License v3.0 (AGPL-3.0)

Acknowledgments

Built on top of excellent open source projects:

  • Software Heritage for archive access and SWHID generation
  • SCANOSS for code fingerprinting