Files
2026-09-30 20:30:56 +03:00

28 lines
2.3 KiB
Markdown

## Why
DockerHub discovery admitted a large deduplicated repository backlog, but FIFO resolution and the hidden three-image selector cap cannot produce a fair, bounded comparison across all configured keywords. A controlled 24-48 hour experiment is needed to measure keyword yield and the marginal value of image versions beyond the current first three without allowing the backlog to monopolize runtime capacity.
## What Changes
- Add durable many-to-many DockerHub keyword-to-repository provenance so deduplicated targets retain every discovery attribution.
- Add a reversible experiment hold and a round-robin cohort planner that takes up to ten genuinely fresh repositories per configured keyword after one complete pinned deep pass, preserving honest shortfalls without substituting historical targets.
- Scan one current image from each cohort repository and up to ten distinct image graphs from one version-rich deep probe per keyword.
- Enforce a global experiment ceiling of 1,200 unique immutable images and keep non-cohort/new repositories cold until reviewed reactivation.
- Replace the hidden three-image clamp with explicit fail-closed configuration validation and deterministic selection beyond the third image.
- Persist image rank, selection reason, manifest layer graph, layer digest, and base/top layer positions for per-keyword experiment reporting.
- Report first-three versus later-version yield using deduplicated findings, credential identities, verification outcomes, scan time, and coverage.
## Capabilities
### New Capabilities
- `docker-depth-experiment`: Durable provenance, bounded fair cohort scheduling, configurable image depth, reversible holds, layer attribution, and experiment reporting.
### Modified Capabilities
## Impact
- PostgreSQL schema and managed migrations for Docker discovery provenance, experiment cohorts, image selection metadata, and durable reporting state.
- DockerHub page admission, repository resolver scheduling, immutable target creation, and finding attribution in `app/scanner_db.py`, `app/scanner.py`, and `app/console_runner.py`.
- DockerHub configuration and validation in `app/config.yaml` and runner argument construction.
- Focused unit/PostgreSQL integration tests plus canonical offline migration and supervised runtime rollout.