fix(scanner): bound memory and accelerate full scans - #174
Merged
Merged
Conversation
alxxjohn
added a commit
that referenced
this pull request
Sep 1, 2026
🤖 I have created a release *beep* *boop* --- ## [1.9.0](v1.8.3...v1.9.0) (2026-09-01) ### Features * **scanner:** support bounded vendored source scans ([11e8b3e](11e8b3e)) ### Bug Fixes * **ci:** document safe test profile read ([cc307b2](cc307b2)) * **scanner:** bound and accelerate full scans ([fad10f2](fad10f2)) * **scanner:** bound memory and accelerate full scans ([#174](#174)) ([24cb12c](24cb12c)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This fixes repository-wide full scans that could remain CPU-active for more than ten minutes while growing to multiple GiB of memory on mixed Go and TypeScript/AWS CDK repositories.
The change makes full-scan work bounded, removes repeated TypeScript regex compilation, adds progress and heap diagnostics, and introduces repeatable cold/warm full-scan and clone-index benchmarks.
Root-cause evidence
A repeated cold full-scan profile showed approximately 39 percent of allocation space in regexp compilation, primarily from recompiling the same child_process and vm TypeScript binding patterns for every file. Repository-wide corpus and clone structures also retained work without aggregate byte, token, window, or entry limits.
Changes
Bounded repository corpus
Bounded and faster clone analysis
TypeScript security scan optimization
Operator diagnostics
Configurable vendored-source analysis
scan_vendored_source: truefor repositories that commit or patch vendored code.-folderand configured target roots from bypassingvendor,node_modules, orcdk.outpolicy.excludepatterns authoritative when vendored-source scanning is enabled.Benchmarks
Synthetic mixed repository benchmark on Apple M4 arm64 with 64 Go files, 64 TypeScript files, and generated node_modules, vendor, and cdk.out trees:
Current warm-cache result: 14.09 ms/op, 15.10 MB/op, and 55,199 allocations/op.
Follow-up full-scan matrix after adding configurable vendored-source analysis (Apple M4 arm64, median of three runs):
The default path stays within the bounded post-fix allocation profile. The opt-in case performs and retains more analysis in proportion to the explicitly admitted vendored source while remaining subject to the same hard corpus limits.
High-entropy clone window benchmark:
Edge and regression coverage
Added coverage for:
Verification
Operational note
If a repository exceeds a hard corpus or clone budget, CodeGuard completes with an informational diagnostic indicating degraded analysis rather than risking unbounded memory growth. Repository-specific generated paths should still be added to exclude where appropriate.