## Why DockerHub discovery admitted a large deduplicated repository backlog, but FIFO resolution and the hidden three-image selector cap cannot produce a fair, bounded comparison across all configured keywords. A controlled 24-48 hour experiment is needed to measure keyword yield and the marginal value of image versions beyond the current first three without allowing the backlog to monopolize runtime capacity. ## What Changes - Add durable many-to-many DockerHub keyword-to-repository provenance so deduplicated targets retain every discovery attribution. - Add a reversible experiment hold and a round-robin cohort planner that takes up to ten genuinely fresh repositories per configured keyword after one complete pinned deep pass, preserving honest shortfalls without substituting historical targets. - Scan one current image from each cohort repository and up to ten distinct image graphs from one version-rich deep probe per keyword. - Enforce a global experiment ceiling of 1,200 unique immutable images and keep non-cohort/new repositories cold until reviewed reactivation. - Replace the hidden three-image clamp with explicit fail-closed configuration validation and deterministic selection beyond the third image. - Persist image rank, selection reason, manifest layer graph, layer digest, and base/top layer positions for per-keyword experiment reporting. - Report first-three versus later-version yield using deduplicated findings, credential identities, verification outcomes, scan time, and coverage. ## Capabilities ### New Capabilities - `docker-depth-experiment`: Durable provenance, bounded fair cohort scheduling, configurable image depth, reversible holds, layer attribution, and experiment reporting. ### Modified Capabilities ## Impact - PostgreSQL schema and managed migrations for Docker discovery provenance, experiment cohorts, image selection metadata, and durable reporting state. - DockerHub page admission, repository resolver scheduling, immutable target creation, and finding attribution in `app/scanner_db.py`, `app/scanner.py`, and `app/console_runner.py`. - DockerHub configuration and validation in `app/config.yaml` and runner argument construction. - Focused unit/PostgreSQL integration tests plus canonical offline migration and supervised runtime rollout.