28 lines
1.9 KiB
Markdown
28 lines
1.9 KiB
Markdown
## Why
|
|
|
|
The core DockerHub, GitHub, and GitLab sources spend most of their scan budget on repeated image contents or mutable repository snapshots, while recent strict-usable yield remains near zero. The scanner needs to cover materially different Docker layers and bind Git work to exact revisions so that additional work buys new evidence rather than another pass over the same surface.
|
|
|
|
## What Changes
|
|
|
|
- Select up to three Docker images per repository whose ordered layer graphs are distinct, instead of stopping at the first eligible tag.
|
|
- Prefer the newest graph, a graph adding the most not-yet-selected layers, and an older divergent graph while continuing to deduplicate immutable digest targets.
|
|
- Resolve Git discovery observations into immutable ref and commit identities before scanning.
|
|
- Scan all commits introduced since the last successfully covered commit for that ref, rather than relying on a moving repository URL, age cutoff, and depth cap.
|
|
- Persist immutable Git scan plans and successfully covered heads; never advance exact coverage on a failed or unpinned fallback scan.
|
|
- Bound API enumeration and Docker/Git expansion through explicit configuration and report partial or inexact coverage honestly.
|
|
|
|
## Capabilities
|
|
|
|
### New Capabilities
|
|
|
|
- `docker-layer-graph-selection`: Bounded selection of materially distinct platform-specific Docker image layer graphs.
|
|
- `git-ref-delta-scanning`: Immutable, per-ref Git scan planning and successful incremental coverage tracking.
|
|
|
|
### Modified Capabilities
|
|
|
|
None.
|
|
|
|
## Impact
|
|
|
|
The change affects Docker Hub tag and registry-manifest resolution, GitHub and GitLab metadata resolution, source-cycle configuration, PostgreSQL queue/reservation/scan state, TruffleHog command construction, and focused scanner/runtime integration tests. It adds bounded registry and source API requests but does not change external service APIs or credential output formats.
|