## 1. Docker Lifecycle Policy - [x] 1.1 Add `--local-dev` only to Docker TruffleHog command construction while retaining existing containment and `--no-update`. - [x] 1.2 Record the `finished scanning` marker and classify missing completion, unexplained RC=1, and wrapper exit outcomes with explicit retryable error classes. - [x] 1.3 Confirm incomplete outcomes use the existing three-attempt queue policy and preserve partial findings. - [x] 1.4 Add source-configured Docker internal concurrency 4 and target timeout 600 seconds. - [x] 1.5 Classify the exact detector context-timeout message as nonfatal degraded coverage. ## 2. Regression Coverage - [x] 2.1 Add command-construction tests proving Docker receives `--local-dev` and non-Docker commands do not. - [x] 2.2 Add diagnostic tests for complete RC=0, missing-marker RC=0, incomplete RC=1, wrapper-exit RC=1, and unchanged non-Docker behavior. - [x] 2.3 Add queue-policy coverage for deferred attempts, terminal attempt exhaustion, and partial-finding preservation. - [x] 2.4 Run focused scanner tests and the relevant broader regression suite with bytecode writes disabled. - [x] 2.5 Add resource-plumbing and detector-timeout regression coverage, then rerun affected tests. ## 3. Validation And Rollout - [x] 3.1 Run strict OpenSpec validation and verify the implementation against the change artifacts. - [x] 3.2 Restart the managed runtime and confirm PostgreSQL, pipeline workers, scan slots, and Docker source health. - [x] 3.3 Observe the Docker lifecycle canary for at least 100 attempts or two hours before historical replay. - [x] 3.4 Requeue one bounded batch of exact-signature historical failures and verify completion, deduplication, and queue drain.