3.0 KiB
3.0 KiB
ADDED Requirements
Requirement: External GitLab scan lifecycle ownership
The system SHALL bypass TruffleHog's embedded overseer for configured GitLab repository scans while retaining external supervision, scan-slot leases, timeout enforcement, output bounds, and Windows Job containment.
Scenario: GitLab command construction
- WHEN the GitLab source constructs a TruffleHog Git command with external lifecycle enabled
- THEN the command includes both
--local-devand--no-update
Scenario: Non-GitLab command construction
- WHEN another source constructs a TruffleHog Git command without external lifecycle enabled
- THEN the command does not gain
--local-devor GitLab completion policy
Requirement: Explicit GitLab scan completion
The system SHALL require both exit code 0 and the exact finished scanning marker before treating an externally managed GitLab TruffleHog process as complete.
Scenario: Normal GitLab completion
- WHEN the process exits code 0 after emitting
finished scanning - THEN completion metadata is recorded and no lifecycle error is added
Scenario: Missing GitLab completion marker
- WHEN the process exits without emitting
finished scanning - THEN the result is classified as retryable
command_incompleteand is not treated as complete
Scenario: Nonzero exit after completion marker
- WHEN the process emits
finished scanningand exits nonzero without a more specific fatal diagnostic - THEN the result is classified as retryable
wrapper_exit
Requirement: Bounded retry for incomplete GitLab scans
The system SHALL route incomplete GitLab lifecycle outcomes through the existing bounded target retry policy.
Scenario: Retry remains available
- WHEN an incomplete GitLab scan occurs before the configured maximum target attempt
- THEN the queue defers the target using the configured retry delay
Scenario: Attempt limit is reached
- WHEN an incomplete GitLab scan occurs at the maximum target attempt
- THEN the queue records a terminal failed target without an unbounded loop
Requirement: Partial GitLab finding preservation
The system SHALL retain findings emitted before an incomplete GitLab process exit without representing the repository as fully scanned.
Scenario: Findings precede incomplete exit
- WHEN TruffleHog emits findings and then exits before completion is confirmed
- THEN those findings remain durable while the target receives retryable incomplete disposition
Requirement: Controlled GitLab lifecycle rollout
The system SHALL enable and replay GitLab lifecycle behavior only through bounded, observable stages.
Scenario: Canary has not passed
- WHEN the GitLab lifecycle canary has not reached its observation threshold
- THEN historical terminal failures are not mass-requeued
Scenario: Canary has passed
- WHEN the canary is healthy and a bounded exact-signature batch is selected
- THEN only targets in that batch are returned to the pending queue