Skip to content

1.4.0

Latest

Choose a tag to compare

@oscarvalenzuelab oscarvalenzuelab released this 01 Sep 19:44
· 1 commit to main since this release
cd6c0d8

Fixed

Keyword search runs only when asked for, and only when nothing else answered (#59).

before (no --enable-fuzzy, against express@4.18.2):
  exact  0.85  pkg:npm/express@4.18.2  express
  fuzzy  0.83  None                    senam5jari-975
  fuzzy  0.83  None                    voiti-1xbet-rech-idet-urxfhkrm
  ... eight more

after:
  exact  0.9   pkg:npm/express@4.18.2  express

Two hundredths of confidence separated express from npm spam, close enough that --confidence-threshold could not tell them apart, and the spam carried purl: null so nothing downstream could act on it.

Keyword search matches on the project name, so it answers with whatever else shares that name. There were two call sites: the fuzzy fallback checked the flag, and the one in phase 1 checked nothing. The second also ran before the manifest parsing in phase 2 that produces the exact match, so with Software Heritage off, which is the default, it fired on every run. The flag's help says fuzzy runs when exact matches fail; whether they had failed was not known at that point.

Both are gone. The search runs once, after everything else has had its turn, when nothing was identified and --enable-fuzzy was passed. The same fallback inside the Software Heritage path is removed rather than gated, so every route goes through the one place.

input flag before after
express none 1 exact + 10 fuzzy 1 exact
express --enable-fuzzy 1 exact + 10 fuzzy 1 exact
unidentifiable directory none 10 fuzzy none
unidentifiable directory --enable-fuzzy 10 fuzzy 10 fuzzy

Changed

A run without --enable-fuzzy against a directory nothing can identify now returns no results where it used to return keyword matches. They were never asked for and could not be acted on, but a caller counting results will see the difference. Pass --enable-fuzzy to restore them.

Not changed

The issue also notes express coming back with "official": false. is_official_organization checks a hardcoded list of about thirty organisations that does not include expressjs, so the field means "in our known-official list" rather than "is the canonical repository". Widening or replacing that list is a separate decision.

Full changelog: v1.3.5...v1.4.0