Artifact Analysis
Artifact Analysis is the Google Cloud service that scans container images in Artifact Registry for known vulnerabilities. The GCP Enterprise Baseline turns it on for every image repository in acme-core-artifacts, so each image is scanned when it is pushed, on top of the scan the code pipelines run before the push.
What it does
With automatic scanning on, Artifact Analysis scans an image's operating system packages and language packages when the image is pushed to Artifact Registry. It then keeps the results current as new vulnerability data is published, for images pushed or pulled in the last 30 days. Each vulnerability occurrence names the CVE (Common Vulnerabilities and Exposures) entry, its severity, the affected package and the version that fixes it, and is shown on the image in Artifact Registry and through the Container Analysis API. The service is enabled per project with containerscanning.googleapis.com and set per repository.
How BuiltForProd uses it
The switch. enable_artifact_analysis = true in environments/core/security/security.hcl is on by default; the comment gives the list price of about $0.26 per image scanned on push. The artifact-registry unit then enables the scanning API in acme-core-artifacts and sets every repository's vulnerability scanning to inherit it; with false every repository is set to DISABLED. A change to security.hcl needs the security team's review (CODEOWNERS).
What is scanned. Every image of the platform lives in acme-core-artifacts, one repository per image, with immutable tags:
| Repository | Image |
|---|---|
acme-gcp-blueprint-webapp | The Web App Blueprint's API, run on GKE |
acme-gcp-blueprint-webapp-frontend | The Web App Blueprint's single-page front end, on Cloud Run |
acme-gcp-blueprint-etl-trigger | The Data and ETL Blueprint's trigger service, on Cloud Run |
acme-github-runner | The optional self-hosted runner image |
acme-scc-notifier | The optional Security Command Center notifier image |
Because tags are immutable and a release only adds a tag to an image already in the registry, the image that reaches prod is the same image that was scanned on push.
Before the push. The code repositories scan first: their ci.yml builds each image on every pull request and runs Trivy over it, failing the build on any HIGH or CRITICAL vulnerability that has a fix (ignore-unfixed: true), in operating system packages and libraries. Artifact Analysis then covers the image for vulnerabilities published after it was built.
Platform-wide findings of misconfiguration and threats come from Security Command Center, which the auditor groups read at the organization.
Terms you will see
| Term | Meaning |
|---|---|
| Automatic scanning | Scanning on push, enabled by containerscanning.googleapis.com. |
| Continuous analysis | Updating the findings of recently used images as new vulnerability data arrives. |
| Vulnerability occurrence | One CVE found in one image, with its severity and fixed version. |
INHERITED | The repository setting that follows the project's scanning API. |
| Trivy | The open-source scanner the code pipelines run before an image is pushed. |
Where to read more
- GCP Enterprise Baseline overview and the GCP Web App Blueprint overview.
- Security Command Center for organization-wide findings.
- Immutable artifacts for building an image once and promoting it unchanged.