Files
truf-server/openspec/changes/stabilize-dockerhub-trufflehog-lifecycle/proposal.md
T
2026-09-30 20:30:56 +03:00

1.7 KiB

Why

DockerHub scans frequently terminate with exit code 1 after emitting running source but before finished scanning. These incomplete runs are currently treated as terminal failures after one attempt, which leaves a material coverage gap even though the scanner runtime and target are often healthy.

What Changes

  • Run DockerHub TruffleHog scans without TruffleHog's redundant embedded overseer while retaining the existing external supervisor and Windows Job containment.
  • Record whether TruffleHog emitted its normal completion marker.
  • Classify an unexplained Docker exit without the completion marker as an incomplete transient run instead of a permanent target failure.
  • Reuse the existing bounded target retry policy for incomplete runs.
  • Bound Docker's internal TruffleHog concurrency and allow enough time for a contained full-image scan.
  • Treat TruffleHog's exact detector context-timeout diagnostic as degraded detector coverage rather than a failed image scan.
  • Add a controlled replay path for historical failures matching this exact signature after the canary is healthy.
  • Keep the TruffleHog binary upgrade out of this change so lifecycle behavior can be measured independently.

Capabilities

New Capabilities

  • docker-scan-lifecycle: Defines completion, containment, retry, and replay behavior for DockerHub TruffleHog scans.

Modified Capabilities

None.

Impact

  • Affects Docker command construction and TruffleHog diagnostic classification in app/scanner.py.
  • Affects Docker target completion disposition in the existing PostgreSQL queue flow.
  • Adds focused scanner policy tests and runtime canary checks.
  • Does not change provider keycheck behavior, non-Docker scan commands, or the installed TruffleHog binary.