## Why One transient GitLab project-search timeout currently terminates the entire supervised source process. Four single-attempt read timeouts caused four avoidable GitLab restarts in the latest runtime window even though the token remained healthy and the same query succeeded after restart. ## What Changes - Retry transient GitLab discovery requests with a small bounded attempt count and delay. - Treat exhausted discovery transport failures as a failed source cycle with backoff instead of terminating the supervised child. - Preserve the current query and authentication state so a failed cycle can resume without a coverage gap. - Add focused retry, exhaustion, state, and non-GitLab isolation coverage. - Keep TruffleHog process lifecycle changes outside this change. ## Capabilities ### New Capabilities - `gitlab-discovery-resilience`: Defines bounded transport retry and nonfatal cycle behavior for GitLab project discovery. ### Modified Capabilities None. ## Impact - Affects GitLab discovery requests and config-cycle error handling in `app/scanner.py` and `app/console_runner.py`. - Adds source configuration for the retry budget and delay. - Does not change GitLab token validity, rate-limit rotation, target scan policy, or other source APIs.