Skip to main content

Artifact Analysis

Artifact Analysis is the Google Cloud service that scans container images in Artifact Registry for known vulnerabilities. The GCP Enterprise Baseline turns it on for every image repository in acme-core-artifacts, so each image is scanned when it is pushed, on top of the scan the code pipelines run before the push.

What it does​

With automatic scanning on, Artifact Analysis scans an image's operating system packages and language packages when the image is pushed to Artifact Registry. It then keeps the results current as new vulnerability data is published, for images pushed or pulled in the last 30 days. Each vulnerability occurrence names the CVE (Common Vulnerabilities and Exposures) entry, its severity, the affected package and the version that fixes it, and is shown on the image in Artifact Registry and through the Container Analysis API. The service is enabled per project with containerscanning.googleapis.com and set per repository.

How BuiltForProd uses it​

The switch. enable_artifact_analysis = true in environments/core/security/security.hcl is on by default; the comment gives the list price of about $0.26 per image scanned on push. The artifact-registry unit then enables the scanning API in acme-core-artifacts and sets every repository's vulnerability scanning to inherit it; with false every repository is set to DISABLED. A change to security.hcl needs the security team's review (CODEOWNERS).

What is scanned. Every image of the platform lives in acme-core-artifacts, one repository per image, with immutable tags:

RepositoryImage
acme-gcp-blueprint-webappThe Web App Blueprint's API, run on GKE
acme-gcp-blueprint-webapp-frontendThe Web App Blueprint's single-page front end, on Cloud Run
acme-gcp-blueprint-etl-triggerThe Data and ETL Blueprint's trigger service, on Cloud Run
acme-github-runnerThe optional self-hosted runner image
acme-scc-notifierThe optional Security Command Center notifier image

Because tags are immutable and a release only adds a tag to an image already in the registry, the image that reaches prod is the same image that was scanned on push.

Before the push. The code repositories scan first: their ci.yml builds each image on every pull request and runs Trivy over it, failing the build on any HIGH or CRITICAL vulnerability that has a fix (ignore-unfixed: true), in operating system packages and libraries. Artifact Analysis then covers the image for vulnerabilities published after it was built.

Platform-wide findings of misconfiguration and threats come from Security Command Center, which the auditor groups read at the organization.

Terms you will see​

TermMeaning
Automatic scanningScanning on push, enabled by containerscanning.googleapis.com.
Continuous analysisUpdating the findings of recently used images as new vulnerability data arrives.
Vulnerability occurrenceOne CVE found in one image, with its severity and fixed version.
INHERITEDThe repository setting that follows the project's scanning API.
TrivyThe open-source scanner the code pipelines run before an image is pushed.

Where to read more​