## 1. Source Wiring - [x] 1.1 Add `postman` to CLI `--source` and `--platform` choices and source-to-platform mapping. - [x] 1.2 Add `postman` queue file support through the existing `queue_files_for_args`, prepare, and mark-checked flow. - [x] 1.3 Add `postman` to supervisor source configuration and dashboard source lists. - [x] 1.4 Add disabled-by-default `sources.postman` configuration with GitHub auth pool, search kinds, backfill/tail controls, cache path, and rate-limit settings. ## 2. Target Model And Cache - [x] 2.1 Define Postman target JSON formats for GitHub code search, npm package, PyPI package, local cache, and future URL targets. - [x] 2.2 Implement Postman target parsing and normalization in `console_runner.py` and `scanner_db.py`. - [x] 2.3 Implement durable Postman cache path resolution under the configured runtime directory. - [x] 2.4 Implement safe cache writes with SHA-256 content hashing, max artifact size checks, and origin metadata preservation. ## 3. GitHub Code Search Discovery - [x] 3.1 Implement GitHub code search queries for `filename:postman_collection.json ` and `filename:postman_environment.json ` based on `search_kinds`. - [x] 3.2 Implement bounded pagination using configured `pages` and `per_page`, respecting the GitHub 1000-result search cap. - [x] 3.3 Convert GitHub code search items into Postman target JSON containing repository, path, SHA, kind, API URL, and HTML URL. - [x] 3.4 Implement latest path commit lookup for `max_file_age_days` filtering. - [x] 3.5 Integrate existing known-page early stop behavior for Postman tail scans. ## 4. GitHub Token Pool And Rate Limits - [x] 4.1 Build a source-local GitHub token pool from configured `auth_pool` entries and fallback token settings. - [x] 4.2 Rotate tokens per GitHub code search, commit lookup, and content download request. - [x] 4.3 Mark only the failing token unavailable on primary rate limit, secondary rate limit, auth invalid, or auth forbidden responses. - [x] 4.4 Sleep until earliest known reset time, or configured fallback cooldown, when all GitHub tokens are unavailable. - [x] 4.5 Record token cooldown status in the source runtime state without exposing token values in logs or database snapshots. ## 5. Postman Artifact Scanning - [x] 5.1 Implement Postman content download from GitHub Contents API and cache it before scanning. - [x] 5.2 Implement `scan_postman_target()` to stage cached JSON in a temporary directory and run TruffleHog filesystem scanning. - [x] 5.3 Add Postman branch to `scan_targets_batch()` and pass timeout, detectors, excluded detectors, and verification flags. - [x] 5.4 Preserve nearby file context and apply existing noisy finding filters to Postman scan results. - [x] 5.5 Ensure Postman findings, errors, skipped reasons, and clean scans are persisted through existing JSONL and scanner database writes. ## 6. npm And PyPI Harvesting - [x] 6.1 Add a Postman artifact finder for extracted package directories that matches collection and environment filename patterns. - [x] 6.2 Cache npm package Postman artifacts before package temp directory cleanup and attach npm origin metadata. - [x] 6.3 Cache PyPI package Postman artifacts before package temp directory cleanup and attach PyPI origin metadata. - [x] 6.4 Enqueue harvested package artifacts into `todo_postman.txt` after package scan batches without failing the original package scan. - [x] 6.5 Deduplicate harvested package artifacts by content hash before enqueueing. ## 7. Postman-Aware Enrichment - [x] 7.1 Parse Postman collection and environment JSON into request, auth, header, query, body, and variable context maps. - [x] 7.2 Correlate TruffleHog finding locations or nearby context with Postman context maps. - [x] 7.3 Classify credential kind and provider using DetectorName, value shape, auth/header type, variable name, and endpoint host. - [x] 7.4 Detect common placeholders and assign placeholder or low-confidence classification. - [x] 7.5 Persist enrichment fields using existing finding enrichment/database columns where possible. ## 8. Observability And Configuration - [x] 8.1 Add Postman source cycle metrics, queue snapshots, target scan records, findings, and errors to existing database flows. - [x] 8.2 Add Postman queue counts to dashboard current queues and source health views. - [x] 8.3 Add redaction coverage for Postman/GitHub auth pool settings in config snapshots and logs. - [x] 8.4 Add backfill-friendly and tail-friendly config examples in `config.yaml` comments. ## 9. Verification - [x] 9.1 Run a small Postman GitHub discovery cycle with `pages: 1`, `per_page: 10`, and `max_targets` set. - [x] 9.2 Re-run the same cycle and verify duplicate targets are skipped through `todo_postman.txt` and `checked_postman.txt`. - [x] 9.3 Verify all-token rate-limit fallback with a simulated or controlled token-unavailable state. - [x] 9.4 Verify npm and PyPI harvesting using a package fixture containing collection and environment JSON files. - [x] 9.5 Verify database and dashboard visibility for Postman source cycles, queues, target scans, findings, and errors. - [x] 9.6 Run `openspec status --change add-postman-source` and ensure all implementation tasks are complete before archive.