Files
T
2026-09-30 20:30:56 +03:00

1.9 KiB

ADDED Requirements

Requirement: Configurable Larger Artifact Coverage

The scanner SHALL allow package, Postman, GitHub Actions, and GitLab CI artifact size limits to be raised through configuration without code changes.

Scenario: Package artifact limit is increased

  • WHEN npm or PyPI max_artifact_size_mb is configured to a larger value
  • THEN package scans SHALL use the configured size limit for download and scan decisions

Scenario: CI artifact limits are increased

  • WHEN GitHub Actions or GitLab CI artifact archive and file limits are configured to larger values
  • THEN CI scans SHALL use those configured limits for artifact download and extraction decisions

Requirement: Conservative Concurrency Preserved

The scanner SHALL preserve per-source worker controls so larger artifact limits do not automatically increase concurrent heavy scans.

Scenario: Size limits increase with unchanged workers

  • WHEN artifact size limits are raised in configuration and worker counts are unchanged
  • THEN the scanner SHALL keep using the configured worker counts for the affected source

Requirement: Oversized Artifact Visibility

The scanner SHALL record existing oversized-artifact skip reasons in logs and target scan records using the current result model.

Scenario: Artifact remains over configured limit

  • WHEN an artifact exceeds the configured size limit
  • THEN the scanner SHALL record a skipped result with the size-limit reason using existing logging and target scan recording paths

Requirement: No New Queue Semantics

The scanner SHALL NOT introduce a deferred or deep artifact queue as part of this change.

Scenario: Artifact is too large for current run

  • WHEN an artifact is skipped because it exceeds the configured limit
  • THEN the scanner SHALL handle it through the current scan result and queue behavior without creating a new queue type