## Why DockerHub scans frequently terminate with exit code 1 after emitting `running source` but before `finished scanning`. These incomplete runs are currently treated as terminal failures after one attempt, which leaves a material coverage gap even though the scanner runtime and target are often healthy. ## What Changes - Run DockerHub TruffleHog scans without TruffleHog's redundant embedded overseer while retaining the existing external supervisor and Windows Job containment. - Record whether TruffleHog emitted its normal completion marker. - Classify an unexplained Docker exit without the completion marker as an incomplete transient run instead of a permanent target failure. - Reuse the existing bounded target retry policy for incomplete runs. - Bound Docker's internal TruffleHog concurrency and allow enough time for a contained full-image scan. - Treat TruffleHog's exact detector context-timeout diagnostic as degraded detector coverage rather than a failed image scan. - Add a controlled replay path for historical failures matching this exact signature after the canary is healthy. - Keep the TruffleHog binary upgrade out of this change so lifecycle behavior can be measured independently. ## Capabilities ### New Capabilities - `docker-scan-lifecycle`: Defines completion, containment, retry, and replay behavior for DockerHub TruffleHog scans. ### Modified Capabilities None. ## Impact - Affects Docker command construction and TruffleHog diagnostic classification in `app/scanner.py`. - Affects Docker target completion disposition in the existing PostgreSQL queue flow. - Adds focused scanner policy tests and runtime canary checks. - Does not change provider keycheck behavior, non-Docker scan commands, or the installed TruffleHog binary.