1.5 KiB
1.5 KiB
Why
Recent GitLab repository scans produced 12 exit-code-1 outcomes without a fatal diagnostic or finished scanning marker. All were treated as non-retryable terminal failures after one attempt, leaving the same process-lifecycle coverage gap previously observed and corrected for Docker scans.
What Changes
- Run GitLab TruffleHog Git scans without TruffleHog's redundant embedded overseer while retaining external supervision, scan-slot control, timeout enforcement, and Windows Job containment.
- Require the normal completion marker before treating a GitLab scan process as complete.
- Classify incomplete or unexplained GitLab process exits as retryable through the existing three-attempt target policy.
- Preserve findings emitted before an incomplete exit.
- Run a GitLab-only canary before replaying a bounded exact-signature historical batch.
- Keep GitHub, package Git, and other Git scan behavior unchanged.
Capabilities
New Capabilities
gitlab-scan-lifecycle: Defines external lifecycle ownership, explicit completion, bounded retry, and controlled replay for GitLab repository scans.
Modified Capabilities
None.
Impact
- Affects GitLab command construction and TruffleHog diagnostic disposition in
app/scanner.pyand source plumbing inapp/console_runner.py. - Adds focused scanner and queue-policy regression coverage.
- Does not change GitLab discovery requests, non-GitLab commands, detector selection, keychecks, or the installed TruffleHog binary.