1.9 KiB
1.9 KiB
ADDED Requirements
Requirement: Configurable Larger Artifact Coverage
The scanner SHALL allow package, Postman, GitHub Actions, and GitLab CI artifact size limits to be raised through configuration without code changes.
Scenario: Package artifact limit is increased
- WHEN npm or PyPI
max_artifact_size_mbis configured to a larger value - THEN package scans SHALL use the configured size limit for download and scan decisions
Scenario: CI artifact limits are increased
- WHEN GitHub Actions or GitLab CI artifact archive and file limits are configured to larger values
- THEN CI scans SHALL use those configured limits for artifact download and extraction decisions
Requirement: Conservative Concurrency Preserved
The scanner SHALL preserve per-source worker controls so larger artifact limits do not automatically increase concurrent heavy scans.
Scenario: Size limits increase with unchanged workers
- WHEN artifact size limits are raised in configuration and worker counts are unchanged
- THEN the scanner SHALL keep using the configured worker counts for the affected source
Requirement: Oversized Artifact Visibility
The scanner SHALL record existing oversized-artifact skip reasons in logs and target scan records using the current result model.
Scenario: Artifact remains over configured limit
- WHEN an artifact exceeds the configured size limit
- THEN the scanner SHALL record a skipped result with the size-limit reason using existing logging and target scan recording paths
Requirement: No New Queue Semantics
The scanner SHALL NOT introduce a deferred or deep artifact queue as part of this change.
Scenario: Artifact is too large for current run
- WHEN an artifact is skipped because it exceeds the configured limit
- THEN the scanner SHALL handle it through the current scan result and queue behavior without creating a new queue type