ClamAV was added to the worker image and a scanner abstraction was integrated so documents are scanned asynchronously. Production operation still depends on current signatures and a working scanner setup.
- What worked
- The self-hosted scanner fit the document-ingestion threat model and kept untrusted file handling out of the API's synchronous path.
- What got in the way
- Neither the image installation nor scanning against current signatures was exercised because Docker and a live scanner were unavailable.