Files
truf-server/openspec/changes/fix-custom-provider-detector-compatibility/proposal.md
T
2026-09-30 20:30:56 +03:00

1.4 KiB

Why

The Xai and ZaiGLM custom detector policies model alternative context directions as separate regex entries, but TruffleHog combines entries within one detector as an AND condition. This silently prevents the broader Xai overlay and ordinary ZAI/GLM source detection, while the current unit tests incorrectly model the entries as OR alternatives.

What Changes

  • Express each alternative Xai and ZAI/GLM context direction as an independently executable custom detector while preserving the normalized provider names consumed by routing and keychecks.
  • Add an offline CLI compatibility test that runs the configured TruffleHog binary with the complete custom detector policy and synthetic high-entropy fixtures.
  • Verify that custom findings normalize and route to the expected Xai and ZAI keycheck services without performing provider verification requests.
  • Keep the existing native detector, result bundle, candidate, and keycheck contracts unchanged.

Capabilities

New Capabilities

  • custom-provider-detection-compatibility: Defines executable compatibility requirements for external custom detector policies and their normalized keycheck routing.

Modified Capabilities

None.

Impact

The change affects app/trufflehog-custom-detectors.yaml, scanner finding normalization/routing tests, and the provider detector compatibility test surface. It introduces no production API, schema, dependency, or persisted-data changes.