Files
truf-server/openspec/changes/stabilize-and-widen-scanner-coverage/tasks.md
T
2026-09-30 20:30:56 +03:00

3.3 KiB

1. Runtime Stability

  • 1.1 Update console_runner.save_state() to write through a unique temp file per attempt.
  • 1.2 Add bounded retry/backoff around os.replace for transient PermissionError and related Windows access errors.
  • 1.3 Ensure failed state replacement after retries still surfaces the final error.
  • 1.4 Add or run a focused smoke test that simulates state writes while the state file is repeatedly read.

2. Artifact Size Coverage

  • 2.1 Increase package artifact size limits in config.yaml while keeping npm/PyPI worker counts unchanged.
  • 2.2 Increase Postman artifact size limits in config.yaml while keeping Postman worker counts unchanged.
  • 2.3 Increase GitHub Actions and GitLab CI artifact archive/file limits in config.yaml while keeping CI worker counts unchanged.
  • 2.4 Verify oversized artifacts still record existing skipped reasons in logs and target scan records.

3. Metadata Discovery Targeting

  • 3.1 Review default repository/package/image metadata query lists and keep generic api_key, secret, and token terms out of those defaults.
  • 3.2 Add or retain provider/framework metadata queries for high-signal discovery terms such as Qwen, DashScope, Groq, OpenRouter, LiteLLM, LangChain, and LlamaIndex.
  • 3.3 Ensure exact env var/API host terms are used only for content-oriented discovery paths such as Postman/API artifacts, code-like artifact search, or CI artifacts.

4. Package Git Discovery

  • 4.1 Extend package metadata extraction to inspect repository, homepage, bugs, and related package metadata fields for GitHub/GitLab repository URLs.
  • 4.2 Canonicalize package-derived repository URLs by removing .git, issue paths, branch/tree paths, and other non-repository suffixes when possible.
  • 4.3 Deduplicate package git targets by normalized repository URL before queueing.
  • 4.4 Gradually increase package_git.pages and verify target volume, duplicate rate, and source runtime remain acceptable.

5. CI Seed Selection

  • 5.1 Improve GitHub Actions seed parsing from scanner DB target scans, findings, and package git candidate records.
  • 5.2 Improve GitLab CI seed parsing from scanner DB target scans, findings, and package git candidate records.
  • 5.3 Verify skipped_unparseable counts decrease for CI source discovery.
  • 5.4 Increase ci_seed_scan_limit and ci_max_repos_per_cycle modestly after seed parsing improves.
  • 5.5 Verify CI sources still respect configured worker and artifact limits.

6. Provider Validation Pattern

  • 6.1 Keep Qwen/DashScope context routing from sending strong Qwen-context sk-... keys to unrelated generic checkers.
  • 6.2 Pick the next provider candidate with a safe non-generating validation endpoint.
  • 6.3 Add the next provider using the detector plus keychecker pattern.
  • 6.4 Ensure new provider keycheck results include stable detector names and metadata for DB link repair.

7. Verification

  • 7.1 Run Python compilation checks for modified Python modules.
  • 7.2 Validate OpenSpec specs and task status for this change.
  • 7.3 Run targeted smoke commands for state persistence, package discovery, and CI seed discovery.
  • 7.4 Inspect supervisor status and recent logs after deployment to confirm source restarts and skipped/unparseable counts improved.