Wire the scan-plan builder into a runnable pipeline that scans an OnboardedTarget:
- AgentConfig.unified_pipeline (env UNIFIED_PIPELINE, default off). agent.run_scan
dispatches to run_target when set, else the legacy run().
- orchestrator::run_target: loads the target from onboarded_targets, creates a
ScanRun, and runs run_target_pipeline; run_target_pipeline builds the scan plan
and, for a code (git) artifact, reuses the full legacy pipeline via a
TrackedRepository view (clone → SAST umbrella → triage → persist → issues →
DAST) then syncs findings_count + the git watermark back to the target.
Firmware/PLC/mobile scanners are follow-ups (#128/#129/#130); URL-only targets
attempt DAST.
- repo_view_from_target: inverse of the migration's repo_to_target, _id-preserving.
Additive + flag-gated: the legacy path is unchanged and default. Unit tests for
repo_view_from_target (+ the part-1 build_scan_plan tests). Full E2E verification
is via UNIFIED_PIPELINE=1 on a running instance.
Closes#133.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
build_scan_plan(target) turns an OnboardedTarget into the ordered set of scans to
run, each bound to the artifact it consumes: matrix defaults (applicable_scans)
intersected with the target's scan_config enable/disable overrides. Pure and
fully unit-tested; the decision engine that run_target will execute next.
Refs #133.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>