Files
truf-server/openspec/changes/fix-custom-provider-detector-compatibility/proposal.md
T
2026-09-30 20:30:56 +03:00

24 lines
1.4 KiB
Markdown

## Why
The Xai and ZaiGLM custom detector policies model alternative context directions as separate regex entries, but TruffleHog combines entries within one detector as an AND condition. This silently prevents the broader Xai overlay and ordinary ZAI/GLM source detection, while the current unit tests incorrectly model the entries as OR alternatives.
## What Changes
- Express each alternative Xai and ZAI/GLM context direction as an independently executable custom detector while preserving the normalized provider names consumed by routing and keychecks.
- Add an offline CLI compatibility test that runs the configured TruffleHog binary with the complete custom detector policy and synthetic high-entropy fixtures.
- Verify that custom findings normalize and route to the expected Xai and ZAI keycheck services without performing provider verification requests.
- Keep the existing native detector, result bundle, candidate, and keycheck contracts unchanged.
## Capabilities
### New Capabilities
- `custom-provider-detection-compatibility`: Defines executable compatibility requirements for external custom detector policies and their normalized keycheck routing.
### Modified Capabilities
None.
## Impact
The change affects `app/trufflehog-custom-detectors.yaml`, scanner finding normalization/routing tests, and the provider detector compatibility test surface. It introduces no production API, schema, dependency, or persisted-data changes.