Skip to content

feat(search): ioc --with-artifacts returns the matching artifacts' metadata - #275

Merged
vhmartinezm merged 3 commits into
developfrom
DN-8545-ioc-search-artifacts
Sep 30, 2026
Merged

vhmartinezm merged 3 commits into
developfrom
DN-8545-ioc-search-artifacts

Conversation

@vhmartinezm

@vhmartinezm vhmartinezm commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

polyswarm search ioc ip|domain|ttp|imphash <value> gains a --with-artifacts flag. It calls search_by_ioc(with_artifacts=True) and prints each row with the same formatter as search metadata, so the text, json and hash output formats all work. The short_help now covers both directions: "Retrieve IOCs by artifact hash, or artifacts by IOC."

Semantics

  • Without the flag, output is unchanged.
  • On a hash lookup (search ioc sha256 …), the flag is refused as a usage error (exit 2). It is not silently ignored.
  • The SDK floor rises to polyswarm_api>=4.7.0.

Requires

Tests

tests/search_test.py mocks the SDK method, as the repo's testing spec allows. It covers:

  • the flag being passed through;
  • the default call being unchanged;
  • the usage error on hash lookups;
  • the text, json, sha256, sha1 and md5 output formats on a with-artifacts row.

…with_artifacts=)

CI installs the SDK from the same-named branch archive, so the floor names
the version the paired SDK change declares: 4.7.0, the next version above
the 4.6.0 the SDK's develop already declares for refanging. It is mergeable
once that change is on the SDK's develop, and releasable once 4.7.0 is on
PyPI.
…tadata

`search ioc <ip|domain|ttp|imphash> <value>` prints bare sha256s. With
`--with-artifacts` it asks the server for each artifact's metadata-search row
and renders it with the `metadata` formatter, the block `search metadata`
prints, so the text, json and hash output formats all apply. `output.ioc`
cannot render these rows (it indexes IOC keys a metadata row lacks).

Without the flag the SDK call is unchanged. On the sha256/sha1/md5 forward
lookup the flag is refused as a usage error rather than silently ignored.

Tests mock at the SDK boundary with autospec, so each call is a signature
check against the SDK the floor installs.
…rows

Drive sha256, sha1 and md5 through the metadata formatter on an artifact row,
and name the reverse search in the command's short help.
@claude

claude Bot commented Sep 29, 2026

Copy link
Copy Markdown

Clean against AGENTS.md and specs/: it targets develop, leaves the package version alone, raises the SDK floor in the pin, adds a ## Requires link, updates specs 02 and 05, and mocks at the SDK boundary with autospec. One action: the branch name has a ticket prefix, so squash-merge with an explicit clean subject (AGENTS.md § Commit + PR hygiene) so the ticket ID stays out of develop history.

@vhmartinezm
vhmartinezm merged commit 068c8f7 into develop Sep 30, 2026
2 checks passed
@vhmartinezm
vhmartinezm deleted the DN-8545-ioc-search-artifacts branch September 30, 2026 18:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants