Initial server source import

This commit is contained in:
sashatrask
2026-09-30 20:30:56 +03:00
commit 170dd941b9
498 changed files with 261563 additions and 0 deletions
@@ -0,0 +1,30 @@
## Why
DockerHub scans frequently terminate with exit code 1 after emitting `running source` but before `finished scanning`. These incomplete runs are currently treated as terminal failures after one attempt, which leaves a material coverage gap even though the scanner runtime and target are often healthy.
## What Changes
- Run DockerHub TruffleHog scans without TruffleHog's redundant embedded overseer while retaining the existing external supervisor and Windows Job containment.
- Record whether TruffleHog emitted its normal completion marker.
- Classify an unexplained Docker exit without the completion marker as an incomplete transient run instead of a permanent target failure.
- Reuse the existing bounded target retry policy for incomplete runs.
- Bound Docker's internal TruffleHog concurrency and allow enough time for a contained full-image scan.
- Treat TruffleHog's exact detector context-timeout diagnostic as degraded detector coverage rather than a failed image scan.
- Add a controlled replay path for historical failures matching this exact signature after the canary is healthy.
- Keep the TruffleHog binary upgrade out of this change so lifecycle behavior can be measured independently.
## Capabilities
### New Capabilities
- `docker-scan-lifecycle`: Defines completion, containment, retry, and replay behavior for DockerHub TruffleHog scans.
### Modified Capabilities
None.
## Impact
- Affects Docker command construction and TruffleHog diagnostic classification in `app/scanner.py`.
- Affects Docker target completion disposition in the existing PostgreSQL queue flow.
- Adds focused scanner policy tests and runtime canary checks.
- Does not change provider keycheck behavior, non-Docker scan commands, or the installed TruffleHog binary.