When we get results from a front-end ScanCode.io, we may have only PURLs, with little to no extra data.
In particular we may miss the download URL in "skinny" scan results from the "inspect package" pipeline.
PurlDB knows how to collect metadata and run scans on the archives of a package using a PURL input. We need the same from DejaCode.