## Why The completed portion of the Docker depth pilot found every currently alive credential in the newest selected image and no additional alive credential in older image ranks. A larger but still bounded rank-1 cohort is needed to test whether spending the same capacity on repository breadth produces better credential and currently-alive yield than blanket image depth. ## What Changes - Add a separate rank-1-only Docker breadth experiment over exactly 2,000 previously unscanned physical repository anchors from the existing complete frozen discovery pass, excluding the current depth-pilot cohort. - Balance the cohort without using prior yield: each of the 52 keywords with an eligible remaining pool receives 38 repositories and 24 deterministically selected keywords receive one additional repository; the 9 exhausted keywords retain explicit zero coverage. - Deduplicate physical repositories across keywords while preserving all fresh keyword provenance, and scan at most one newest eligible immutable image per selected repository. - Keep the new experiment fail-closed until the current depth experiment is terminal and its cold rows have passed reviewed release; never run two Docker experiment authorities concurrently. - Persist a reviewable immutable cohort plan before activation and retain the existing lease, reservation, fencing, finite-retry, capacity, and reversible hold guarantees. - Report globally deduplicated credentials, currently alive credentials, repository/image coverage, and both yield measures per scanner-hour, with per-keyword attribution and no secret or target material. ## Capabilities ### New Capabilities - `docker-rank1-breadth-experiment`: A balanced, deterministic, physically deduplicated 2,000-repository rank-1 experiment with reviewed authority handoff, bounded execution, and secret-safe yield reporting. ### Modified Capabilities ## Impact - Docker experiment validation, cohort planning, authority handoff, resolver admission, rank-1 target scheduling, and aggregate reporting. - Managed PostgreSQL experiment state and audit evidence, with migrations only where the existing depth-experiment schema cannot represent the new plan. - Docker experiment configuration and focused unit/PostgreSQL integration coverage. - Runtime operations require canonical stop, reviewed release of the completed depth experiment, reviewed activation of this change, and canonical restart.