1.5 KiB
1.5 KiB
Why
OpenAI credential discovery fell from hundreds of new identities to almost none after historical Docker and package backlogs drained. The core GitHub, GitLab, and DockerHub discovery rotations do not contain the literal openai query, even though a read-only production probe showed that exact query exposes previously unseen supply.
What Changes
- Add exact
openaidiscovery to the GitHub, GitLab, and DockerHub core query rotations. - Support narrowly allowlisted per-query bounds so the exact query can use smaller page and target limits without reducing coverage for every other query.
- Bound the first and recurring exact-query windows to one GitHub page, one GitLab page, and two DockerHub pages with source-appropriate scan limits.
- Preserve existing target deduplication, revision-aware rescan limits, queue authority, and Docker digest requirements.
- Measure the exact-query canary from discovery through scans, OpenAI candidates, API checks, and usable outcomes.
Capabilities
New Capabilities
openai-discovery-coverage: Exact provider-term discovery with query-scoped bounds and observable production rollout.
Modified Capabilities
None.
Impact
The change affects app/config.yaml, query argument construction in app/console_runner.py, focused runner/config tests, source-cycle behavior for GitHub/GitLab/DockerHub, and production canary operations. It adds no dependency or schema migration and does not alter HuggingFace, detector routing, keycheck classification, or Docker target identity.