31 lines
1.7 KiB
Markdown
31 lines
1.7 KiB
Markdown
## Why
|
|
|
|
DockerHub scans frequently terminate with exit code 1 after emitting `running source` but before `finished scanning`. These incomplete runs are currently treated as terminal failures after one attempt, which leaves a material coverage gap even though the scanner runtime and target are often healthy.
|
|
|
|
## What Changes
|
|
|
|
- Run DockerHub TruffleHog scans without TruffleHog's redundant embedded overseer while retaining the existing external supervisor and Windows Job containment.
|
|
- Record whether TruffleHog emitted its normal completion marker.
|
|
- Classify an unexplained Docker exit without the completion marker as an incomplete transient run instead of a permanent target failure.
|
|
- Reuse the existing bounded target retry policy for incomplete runs.
|
|
- Bound Docker's internal TruffleHog concurrency and allow enough time for a contained full-image scan.
|
|
- Treat TruffleHog's exact detector context-timeout diagnostic as degraded detector coverage rather than a failed image scan.
|
|
- Add a controlled replay path for historical failures matching this exact signature after the canary is healthy.
|
|
- Keep the TruffleHog binary upgrade out of this change so lifecycle behavior can be measured independently.
|
|
|
|
## Capabilities
|
|
|
|
### New Capabilities
|
|
- `docker-scan-lifecycle`: Defines completion, containment, retry, and replay behavior for DockerHub TruffleHog scans.
|
|
|
|
### Modified Capabilities
|
|
|
|
None.
|
|
|
|
## Impact
|
|
|
|
- Affects Docker command construction and TruffleHog diagnostic classification in `app/scanner.py`.
|
|
- Affects Docker target completion disposition in the existing PostgreSQL queue flow.
|
|
- Adds focused scanner policy tests and runtime canary checks.
|
|
- Does not change provider keycheck behavior, non-Docker scan commands, or the installed TruffleHog binary.
|