1.9 KiB
1.9 KiB
Why
DockerHub repository discovery is currently anonymous even when a managed account pool is configured, so searches are limited to the anonymous 200-result window and partial page failures can silently advance the query rotation. Authenticated probing confirms the configured Hub bearer flow can retrieve at least 30 pages of 100 results, making reliable deeper pagination available without new credentials or dependencies.
What Changes
- Authenticate every managed DockerHub repository-search mode through the configured account pool and existing Hub bearer-token flow.
- BREAKING: when an explicit DockerHub account pool is configured, fail closed if no account can authenticate instead of falling back to anonymous search.
- Support an authenticated search window of up to 30 pages while retaining a bounded code-level limit.
- Retry transient page failures once, rotate accounts for account-specific failures, and reject an incomplete expected page set rather than enqueueing partial discovery results.
- Preserve the current query cursor when pagination fails, while continuing to advance it after complete or objectively exhausted pagination.
- Keep tag resolution, Registry authentication, immutable-digest deduplication, scan retries, and queue disposition unchanged.
Capabilities
New Capabilities
dockerhub-search-pagination: Authenticated, bounded, complete-or-fail DockerHub repository-search pagination using the managed account pool.
Modified Capabilities
None.
Impact
- Affects DockerHub search/authentication in
app/scanner.py, source-cycle failure propagation inapp/console_runner.py, and focused scanner/runner tests. - Reuses existing configured DockerHub accounts, Hub bearer tokens, cooldowns, and auth-event persistence; no new external dependency or credential format is introduced.
- Active query lists, refresh cadence, scan budgets, cold/failed target policy, and layer-aware scanning are out of scope.