## 1. Runtime Safety - [x] 1.1 Canonically stop the live supervisor and verify all managed child processes are down before editing `app` ## 2. Authenticated Search Implementation - [x] 2.1 Make Hub bearer acquisition endpoint-aware and add a `hub_search` response path with explicit-pool fail-closed behavior, account rotation, and two-attempt transient request bounds - [x] 2.2 Raise the search safety cap to 30 pages and make standard pagination fetch page one first, derive the expected range, and reject any incomplete expected page set - [x] 2.3 Route recent-mode repository search through the same authenticated bounded response path - [x] 2.4 Add a DockerHub discovery transport failure path that records a failed source cycle without advancing the query cursor ## 3. Regression Coverage - [x] 3.1 Cover bearer authorization, token refresh, account rotation/cooldown, and explicit-pool no-fallback behavior without exposing secrets - [x] 3.2 Cover the 30-page cap, page-one count boundary, ordered complete results, one transient retry, and rejection of unresolved partial pagination - [x] 3.3 Cover failed-cycle cursor retention and successful-cycle compatibility - [x] 3.4 Run focused and broader relevant scanner/runner test suites ## 4. Runtime Verification - [x] 4.1 Canonically restart the supervisor and verify PostgreSQL, pipeline workers, DockerHub source health, restart counters, and absence of app bytecode artifacts