Initial server source import

This commit is contained in:
sashatrask
2026-09-30 20:30:56 +03:00
commit 170dd941b9
498 changed files with 261563 additions and 0 deletions
@@ -0,0 +1,33 @@
## ADDED Requirements
### Requirement: Configurable Larger Artifact Coverage
The scanner SHALL allow package, Postman, GitHub Actions, and GitLab CI artifact size limits to be raised through configuration without code changes.
#### Scenario: Package artifact limit is increased
- **WHEN** npm or PyPI `max_artifact_size_mb` is configured to a larger value
- **THEN** package scans SHALL use the configured size limit for download and scan decisions
#### Scenario: CI artifact limits are increased
- **WHEN** GitHub Actions or GitLab CI artifact archive and file limits are configured to larger values
- **THEN** CI scans SHALL use those configured limits for artifact download and extraction decisions
### Requirement: Conservative Concurrency Preserved
The scanner SHALL preserve per-source worker controls so larger artifact limits do not automatically increase concurrent heavy scans.
#### Scenario: Size limits increase with unchanged workers
- **WHEN** artifact size limits are raised in configuration and worker counts are unchanged
- **THEN** the scanner SHALL keep using the configured worker counts for the affected source
### Requirement: Oversized Artifact Visibility
The scanner SHALL record existing oversized-artifact skip reasons in logs and target scan records using the current result model.
#### Scenario: Artifact remains over configured limit
- **WHEN** an artifact exceeds the configured size limit
- **THEN** the scanner SHALL record a skipped result with the size-limit reason using existing logging and target scan recording paths
### Requirement: No New Queue Semantics
The scanner SHALL NOT introduce a deferred or deep artifact queue as part of this change.
#### Scenario: Artifact is too large for current run
- **WHEN** an artifact is skipped because it exceeds the configured limit
- **THEN** the scanner SHALL handle it through the current scan result and queue behavior without creating a new queue type