34 lines
1.9 KiB
Markdown
34 lines
1.9 KiB
Markdown
## ADDED Requirements
|
|
|
|
### Requirement: Configurable Larger Artifact Coverage
|
|
The scanner SHALL allow package, Postman, GitHub Actions, and GitLab CI artifact size limits to be raised through configuration without code changes.
|
|
|
|
#### Scenario: Package artifact limit is increased
|
|
- **WHEN** npm or PyPI `max_artifact_size_mb` is configured to a larger value
|
|
- **THEN** package scans SHALL use the configured size limit for download and scan decisions
|
|
|
|
#### Scenario: CI artifact limits are increased
|
|
- **WHEN** GitHub Actions or GitLab CI artifact archive and file limits are configured to larger values
|
|
- **THEN** CI scans SHALL use those configured limits for artifact download and extraction decisions
|
|
|
|
### Requirement: Conservative Concurrency Preserved
|
|
The scanner SHALL preserve per-source worker controls so larger artifact limits do not automatically increase concurrent heavy scans.
|
|
|
|
#### Scenario: Size limits increase with unchanged workers
|
|
- **WHEN** artifact size limits are raised in configuration and worker counts are unchanged
|
|
- **THEN** the scanner SHALL keep using the configured worker counts for the affected source
|
|
|
|
### Requirement: Oversized Artifact Visibility
|
|
The scanner SHALL record existing oversized-artifact skip reasons in logs and target scan records using the current result model.
|
|
|
|
#### Scenario: Artifact remains over configured limit
|
|
- **WHEN** an artifact exceeds the configured size limit
|
|
- **THEN** the scanner SHALL record a skipped result with the size-limit reason using existing logging and target scan recording paths
|
|
|
|
### Requirement: No New Queue Semantics
|
|
The scanner SHALL NOT introduce a deferred or deep artifact queue as part of this change.
|
|
|
|
#### Scenario: Artifact is too large for current run
|
|
- **WHEN** an artifact is skipped because it exceeds the configured limit
|
|
- **THEN** the scanner SHALL handle it through the current scan result and queue behavior without creating a new queue type
|