## 1. Runtime Stability - [x] 1.1 Update `console_runner.save_state()` to write through a unique temp file per attempt. - [x] 1.2 Add bounded retry/backoff around `os.replace` for transient `PermissionError` and related Windows access errors. - [x] 1.3 Ensure failed state replacement after retries still surfaces the final error. - [x] 1.4 Add or run a focused smoke test that simulates state writes while the state file is repeatedly read. ## 2. Artifact Size Coverage - [x] 2.1 Increase package artifact size limits in `config.yaml` while keeping npm/PyPI worker counts unchanged. - [x] 2.2 Increase Postman artifact size limits in `config.yaml` while keeping Postman worker counts unchanged. - [x] 2.3 Increase GitHub Actions and GitLab CI artifact archive/file limits in `config.yaml` while keeping CI worker counts unchanged. - [x] 2.4 Verify oversized artifacts still record existing skipped reasons in logs and target scan records. ## 3. Metadata Discovery Targeting - [x] 3.1 Review default repository/package/image metadata query lists and keep generic `api_key`, `secret`, and `token` terms out of those defaults. - [x] 3.2 Add or retain provider/framework metadata queries for high-signal discovery terms such as Qwen, DashScope, Groq, OpenRouter, LiteLLM, LangChain, and LlamaIndex. - [x] 3.3 Ensure exact env var/API host terms are used only for content-oriented discovery paths such as Postman/API artifacts, code-like artifact search, or CI artifacts. ## 4. Package Git Discovery - [x] 4.1 Extend package metadata extraction to inspect repository, homepage, bugs, and related package metadata fields for GitHub/GitLab repository URLs. - [x] 4.2 Canonicalize package-derived repository URLs by removing `.git`, issue paths, branch/tree paths, and other non-repository suffixes when possible. - [x] 4.3 Deduplicate package git targets by normalized repository URL before queueing. - [x] 4.4 Gradually increase `package_git.pages` and verify target volume, duplicate rate, and source runtime remain acceptable. ## 5. CI Seed Selection - [x] 5.1 Improve GitHub Actions seed parsing from scanner DB target scans, findings, and package git candidate records. - [x] 5.2 Improve GitLab CI seed parsing from scanner DB target scans, findings, and package git candidate records. - [x] 5.3 Verify `skipped_unparseable` counts decrease for CI source discovery. - [x] 5.4 Increase `ci_seed_scan_limit` and `ci_max_repos_per_cycle` modestly after seed parsing improves. - [x] 5.5 Verify CI sources still respect configured worker and artifact limits. ## 6. Provider Validation Pattern - [x] 6.1 Keep Qwen/DashScope context routing from sending strong Qwen-context `sk-...` keys to unrelated generic checkers. - [x] 6.2 Pick the next provider candidate with a safe non-generating validation endpoint. - [x] 6.3 Add the next provider using the detector plus keychecker pattern. - [x] 6.4 Ensure new provider keycheck results include stable detector names and metadata for DB link repair. ## 7. Verification - [x] 7.1 Run Python compilation checks for modified Python modules. - [x] 7.2 Validate OpenSpec specs and task status for this change. - [x] 7.3 Run targeted smoke commands for state persistence, package discovery, and CI seed discovery. - [x] 7.4 Inspect supervisor status and recent logs after deployment to confirm source restarts and skipped/unparseable counts improved.