Files
2026-09-30 20:30:56 +03:00

2.9 KiB

ADDED Requirements

Requirement: Metadata Discovery Uses High-Signal Queries

Repository, package, and image metadata discovery SHALL prefer provider names, API hosts, framework names, and ecosystem terms over generic secret-related words.

Scenario: Repo metadata query list is reviewed

  • WHEN default repository or package metadata queries are configured
  • THEN broad terms such as api_key, secret, and token SHALL NOT be added by default unless the source searches content rather than metadata

Scenario: Provider query is configured

  • WHEN a provider such as Qwen, DashScope, Groq, or OpenRouter is targeted
  • THEN provider names, API hostnames, and framework terms SHALL be eligible for metadata discovery queries

Requirement: Exact Secret Terms Reserved For Content-Oriented Sources

Exact environment variable and API host searches SHALL be used for content-oriented sources such as Postman/API artifacts, code search, and CI artifacts rather than generic metadata searches.

Scenario: Env var search term is added

  • WHEN an exact term such as DASHSCOPE_API_KEY is added to discovery
  • THEN it SHALL be applied to a source that can inspect file or artifact content

Requirement: Package Git Repository Canonicalization

package_git discovery SHALL canonicalize repository URLs from package metadata before queueing targets.

Scenario: Package metadata contains issue URL

  • WHEN package metadata contains a repository-like URL ending in /issues
  • THEN package_git discovery SHALL normalize it to the canonical repository URL when possible

Scenario: Package metadata contains repository URL variants

  • WHEN package metadata contains .git, branch, tree, or homepage variants for the same repository
  • THEN package_git discovery SHALL avoid queueing duplicate normalized repository targets

Requirement: CI Seed Parsing From Existing Data

GitHub Actions and GitLab CI target discovery SHALL parse repository/project seeds from existing scanner DB records, package git candidates, findings, and target scan metadata where possible.

Scenario: Seed record contains package git target JSON

  • WHEN a CI source examines a package git candidate or target scan record with repository metadata
  • THEN it SHALL derive a GitHub repository or GitLab project seed when the URL provider matches the CI source

Scenario: Seed record cannot identify repository

  • WHEN no repository or project can be derived from a seed record
  • THEN the CI source SHALL count it as unparseable and continue processing other seeds

Requirement: CI Scan Volume Is Configurable

CI source scan volume SHALL remain controlled by existing per-source configuration values.

Scenario: CI seed limit is raised

  • WHEN ci_seed_scan_limit or ci_max_repos_per_cycle is increased in configuration
  • THEN the CI source SHALL use the configured value without requiring code changes