occurrences
Creates, updates, deletes, gets or lists an occurrences resource.
Overview
| Name | occurrences |
| Type | Resource |
| Id | google.containeranalysis.occurrences |
Fields
The following fields are returned by SELECT queries:
- projects_locations_occurrences_get
- projects_locations_notes_occurrences_list
- projects_occurrences_get
- projects_locations_occurrences_list
- projects_notes_occurrences_list
- projects_occurrences_list
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The name of the occurrence in the form of projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]. |
advisoryPublishTime | string (google-datetime) | The time this advisory was published by the source. |
aiSkillAnalysis | object | Describes an AI skill analysis. (id: AISkillAnalysisOccurrence) |
attestation | object | Describes an attestation of an artifact. (id: AttestationOccurrence) |
build | object | Describes a verifiable build. (id: BuildOccurrence) |
compliance | object | Describes a compliance violation on a linked resource. (id: ComplianceOccurrence) |
createTime | string (google-datetime) | Output only. The time this occurrence was created. |
deployment | object | Describes the deployment of an artifact on a runtime. (id: DeploymentOccurrence) |
discovery | object | Describes when a resource was discovered. (id: DiscoveryOccurrence) |
dsseAttestation | object | Describes an attestation of an artifact using dsse. (id: DSSEAttestationOccurrence) |
envelope | object | https://github.com/secure-systems-lab/dsse (id: Envelope) |
image | object | Describes how this resource derives from the basis in the associated note. (id: ImageOccurrence) |
kind | string | Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests. (NOTE_KIND_UNSPECIFIED, VULNERABILITY, BUILD, IMAGE, PACKAGE, DEPLOYMENT, DISCOVERY, ATTESTATION, UPGRADE, COMPLIANCE, DSSE_ATTESTATION, VULNERABILITY_ASSESSMENT, SBOM_REFERENCE, SECRET, AI_SKILL_ANALYSIS) |
noteName | string | Required. Immutable. The analysis note associated with this occurrence, in the form of projects/[PROVIDER_ID]/notes/[NOTE_ID]. This field can be used as a filter in list requests. |
package | object | Describes the installation of a package on the linked resource. (id: PackageOccurrence) |
remediation | string | A description of actions that can be taken to remedy the note. |
resourceUri | string | Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, https://gcr.io/project/image@sha256:123abc for a Docker image. |
sbomReference | object | Describes a specific SBOM reference occurrences. (id: SBOMReferenceOccurrence) |
secret | object | Describes a secret. (id: SecretOccurrence) |
updateTime | string (google-datetime) | Output only. The time this occurrence was last updated. |
upgrade | object | Describes an available package upgrade on the linked resource. (id: UpgradeOccurrence) |
vulnerability | object | Describes a security vulnerability. (id: VulnerabilityOccurrence) |
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The name of the occurrence in the form of projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]. |
advisoryPublishTime | string (google-datetime) | The time this advisory was published by the source. |
aiSkillAnalysis | object | Describes an AI skill analysis. (id: AISkillAnalysisOccurrence) |
attestation | object | Describes an attestation of an artifact. (id: AttestationOccurrence) |
build | object | Describes a verifiable build. (id: BuildOccurrence) |
compliance | object | Describes a compliance violation on a linked resource. (id: ComplianceOccurrence) |
createTime | string (google-datetime) | Output only. The time this occurrence was created. |
deployment | object | Describes the deployment of an artifact on a runtime. (id: DeploymentOccurrence) |
discovery | object | Describes when a resource was discovered. (id: DiscoveryOccurrence) |
dsseAttestation | object | Describes an attestation of an artifact using dsse. (id: DSSEAttestationOccurrence) |
envelope | object | https://github.com/secure-systems-lab/dsse (id: Envelope) |
image | object | Describes how this resource derives from the basis in the associated note. (id: ImageOccurrence) |
kind | string | Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests. (NOTE_KIND_UNSPECIFIED, VULNERABILITY, BUILD, IMAGE, PACKAGE, DEPLOYMENT, DISCOVERY, ATTESTATION, UPGRADE, COMPLIANCE, DSSE_ATTESTATION, VULNERABILITY_ASSESSMENT, SBOM_REFERENCE, SECRET, AI_SKILL_ANALYSIS) |
noteName | string | Required. Immutable. The analysis note associated with this occurrence, in the form of projects/[PROVIDER_ID]/notes/[NOTE_ID]. This field can be used as a filter in list requests. |
package | object | Describes the installation of a package on the linked resource. (id: PackageOccurrence) |
remediation | string | A description of actions that can be taken to remedy the note. |
resourceUri | string | Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, https://gcr.io/project/image@sha256:123abc for a Docker image. |
sbomReference | object | Describes a specific SBOM reference occurrences. (id: SBOMReferenceOccurrence) |
secret | object | Describes a secret. (id: SecretOccurrence) |
updateTime | string (google-datetime) | Output only. The time this occurrence was last updated. |
upgrade | object | Describes an available package upgrade on the linked resource. (id: UpgradeOccurrence) |
vulnerability | object | Describes a security vulnerability. (id: VulnerabilityOccurrence) |
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The name of the occurrence in the form of projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]. |
advisoryPublishTime | string (google-datetime) | The time this advisory was published by the source. |
aiSkillAnalysis | object | Describes an AI skill analysis. (id: AISkillAnalysisOccurrence) |
attestation | object | Describes an attestation of an artifact. (id: AttestationOccurrence) |
build | object | Describes a verifiable build. (id: BuildOccurrence) |
compliance | object | Describes a compliance violation on a linked resource. (id: ComplianceOccurrence) |
createTime | string (google-datetime) | Output only. The time this occurrence was created. |
deployment | object | Describes the deployment of an artifact on a runtime. (id: DeploymentOccurrence) |
discovery | object | Describes when a resource was discovered. (id: DiscoveryOccurrence) |
dsseAttestation | object | Describes an attestation of an artifact using dsse. (id: DSSEAttestationOccurrence) |
envelope | object | https://github.com/secure-systems-lab/dsse (id: Envelope) |
image | object | Describes how this resource derives from the basis in the associated note. (id: ImageOccurrence) |
kind | string | Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests. (NOTE_KIND_UNSPECIFIED, VULNERABILITY, BUILD, IMAGE, PACKAGE, DEPLOYMENT, DISCOVERY, ATTESTATION, UPGRADE, COMPLIANCE, DSSE_ATTESTATION, VULNERABILITY_ASSESSMENT, SBOM_REFERENCE, SECRET, AI_SKILL_ANALYSIS) |
noteName | string | Required. Immutable. The analysis note associated with this occurrence, in the form of projects/[PROVIDER_ID]/notes/[NOTE_ID]. This field can be used as a filter in list requests. |
package | object | Describes the installation of a package on the linked resource. (id: PackageOccurrence) |
remediation | string | A description of actions that can be taken to remedy the note. |
resourceUri | string | Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, https://gcr.io/project/image@sha256:123abc for a Docker image. |
sbomReference | object | Describes a specific SBOM reference occurrences. (id: SBOMReferenceOccurrence) |
secret | object | Describes a secret. (id: SecretOccurrence) |
updateTime | string (google-datetime) | Output only. The time this occurrence was last updated. |
upgrade | object | Describes an available package upgrade on the linked resource. (id: UpgradeOccurrence) |
vulnerability | object | Describes a security vulnerability. (id: VulnerabilityOccurrence) |
| Name | Datatype | Description |
|---|
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The name of the occurrence in the form of projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]. |
advisoryPublishTime | string (google-datetime) | The time this advisory was published by the source. |
aiSkillAnalysis | object | Describes an AI skill analysis. (id: AISkillAnalysisOccurrence) |
attestation | object | Describes an attestation of an artifact. (id: AttestationOccurrence) |
build | object | Describes a verifiable build. (id: BuildOccurrence) |
compliance | object | Describes a compliance violation on a linked resource. (id: ComplianceOccurrence) |
createTime | string (google-datetime) | Output only. The time this occurrence was created. |
deployment | object | Describes the deployment of an artifact on a runtime. (id: DeploymentOccurrence) |
discovery | object | Describes when a resource was discovered. (id: DiscoveryOccurrence) |
dsseAttestation | object | Describes an attestation of an artifact using dsse. (id: DSSEAttestationOccurrence) |
envelope | object | https://github.com/secure-systems-lab/dsse (id: Envelope) |
image | object | Describes how this resource derives from the basis in the associated note. (id: ImageOccurrence) |
kind | string | Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests. (NOTE_KIND_UNSPECIFIED, VULNERABILITY, BUILD, IMAGE, PACKAGE, DEPLOYMENT, DISCOVERY, ATTESTATION, UPGRADE, COMPLIANCE, DSSE_ATTESTATION, VULNERABILITY_ASSESSMENT, SBOM_REFERENCE, SECRET, AI_SKILL_ANALYSIS) |
noteName | string | Required. Immutable. The analysis note associated with this occurrence, in the form of projects/[PROVIDER_ID]/notes/[NOTE_ID]. This field can be used as a filter in list requests. |
package | object | Describes the installation of a package on the linked resource. (id: PackageOccurrence) |
remediation | string | A description of actions that can be taken to remedy the note. |
resourceUri | string | Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, https://gcr.io/project/image@sha256:123abc for a Docker image. |
sbomReference | object | Describes a specific SBOM reference occurrences. (id: SBOMReferenceOccurrence) |
secret | object | Describes a secret. (id: SecretOccurrence) |
updateTime | string (google-datetime) | Output only. The time this occurrence was last updated. |
upgrade | object | Describes an available package upgrade on the linked resource. (id: UpgradeOccurrence) |
vulnerability | object | Describes a security vulnerability. (id: VulnerabilityOccurrence) |
| Name | Datatype | Description |
|---|
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
projects_locations_occurrences_get | select | projectsId, locationsId, occurrencesId | Gets the specified occurrence. | |
projects_locations_notes_occurrences_list | select | projectsId, locationsId, notesId | filter, pageSize, pageToken | Lists occurrences referencing the specified note. Provider projects can use this method to get all occurrences across consumer projects referencing the specified note. |
projects_occurrences_get | select | projectsId, occurrencesId | Gets the specified occurrence. | |
projects_locations_occurrences_list | select | projectsId, locationsId | filter, returnPartialSuccess, pageSize, pageToken | Lists occurrences for the specified project. |
projects_notes_occurrences_list | select | projectsId, notesId | filter, pageSize, pageToken | Lists occurrences referencing the specified note. Provider projects can use this method to get all occurrences across consumer projects referencing the specified note. |
projects_occurrences_list | select | projectsId | pageSize, pageToken, filter, returnPartialSuccess | Lists occurrences for the specified project. |
projects_locations_occurrences_create | insert | projectsId, locationsId | Creates a new occurrence. | |
projects_locations_occurrences_batch_create | insert | projectsId, locationsId | Creates new occurrences in batch. | |
projects_occurrences_batch_create | insert | projectsId | Creates new occurrences in batch. | |
projects_occurrences_create | insert | projectsId | Creates a new occurrence. | |
projects_locations_occurrences_patch | update | projectsId, locationsId, occurrencesId | updateMask | Updates the specified occurrence. |
projects_occurrences_patch | update | projectsId, occurrencesId | updateMask | Updates the specified occurrence. |
projects_locations_occurrences_delete | delete | projectsId, locationsId, occurrencesId | Deletes the specified occurrence. For example, use this method to delete an occurrence when the occurrence is no longer applicable for the given resource. | |
projects_occurrences_delete | delete | projectsId, occurrencesId | Deletes the specified occurrence. For example, use this method to delete an occurrence when the occurrence is no longer applicable for the given resource. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
locationsId | string | |
notesId | string | |
occurrencesId | string | |
projectsId | string | |
filter | string | |
pageSize | integer (int32) | |
pageToken | string | |
returnPartialSuccess | boolean | |
updateMask | string (google-fieldmask) |
SELECT examples
- projects_locations_occurrences_get
- projects_locations_notes_occurrences_list
- projects_occurrences_get
- projects_locations_occurrences_list
- projects_notes_occurrences_list
- projects_occurrences_list
Gets the specified occurrence.
SELECT
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND locationsId = '{{ locationsId }}' -- required
AND occurrencesId = '{{ occurrencesId }}' -- required
;
Lists occurrences referencing the specified note. Provider projects can use this method to get all occurrences across consumer projects referencing the specified note.
SELECT
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND locationsId = '{{ locationsId }}' -- required
AND notesId = '{{ notesId }}' -- required
AND filter = '{{ filter }}'
AND pageSize = '{{ pageSize }}'
AND pageToken = '{{ pageToken }}'
;
Gets the specified occurrence.
SELECT
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND occurrencesId = '{{ occurrencesId }}' -- required
;
Lists occurrences for the specified project.
SELECT
*
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND locationsId = '{{ locationsId }}' -- required
AND filter = '{{ filter }}'
AND returnPartialSuccess = '{{ returnPartialSuccess }}'
AND pageSize = '{{ pageSize }}'
AND pageToken = '{{ pageToken }}'
;
Lists occurrences referencing the specified note. Provider projects can use this method to get all occurrences across consumer projects referencing the specified note.
SELECT
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND notesId = '{{ notesId }}' -- required
AND filter = '{{ filter }}'
AND pageSize = '{{ pageSize }}'
AND pageToken = '{{ pageToken }}'
;
Lists occurrences for the specified project.
SELECT
*
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND pageSize = '{{ pageSize }}'
AND pageToken = '{{ pageToken }}'
AND filter = '{{ filter }}'
AND returnPartialSuccess = '{{ returnPartialSuccess }}'
;
INSERT examples
- projects_locations_occurrences_create
- projects_locations_occurrences_batch_create
- projects_occurrences_batch_create
- projects_occurrences_create
- Manifest
Creates a new occurrence.
INSERT INTO google.containeranalysis.occurrences (
data__build,
data__deployment,
data__name,
data__image,
data__updateTime,
data__upgrade,
data__remediation,
data__sbomReference,
data__secret,
data__createTime,
data__envelope,
data__advisoryPublishTime,
data__noteName,
data__discovery,
data__kind,
data__package,
data__compliance,
data__aiSkillAnalysis,
data__resourceUri,
data__attestation,
data__vulnerability,
data__dsseAttestation,
projectsId,
locationsId
)
SELECT
'{{ build }}',
'{{ deployment }}',
'{{ name }}',
'{{ image }}',
'{{ updateTime }}',
'{{ upgrade }}',
'{{ remediation }}',
'{{ sbomReference }}',
'{{ secret }}',
'{{ createTime }}',
'{{ envelope }}',
'{{ advisoryPublishTime }}',
'{{ noteName }}',
'{{ discovery }}',
'{{ kind }}',
'{{ package }}',
'{{ compliance }}',
'{{ aiSkillAnalysis }}',
'{{ resourceUri }}',
'{{ attestation }}',
'{{ vulnerability }}',
'{{ dsseAttestation }}',
'{{ projectsId }}',
'{{ locationsId }}'
RETURNING
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
;
Creates new occurrences in batch.
INSERT INTO google.containeranalysis.occurrences (
data__occurrences,
projectsId,
locationsId
)
SELECT
'{{ occurrences }}',
'{{ projectsId }}',
'{{ locationsId }}'
RETURNING
occurrences
;
Creates new occurrences in batch.
INSERT INTO google.containeranalysis.occurrences (
data__occurrences,
projectsId
)
SELECT
'{{ occurrences }}',
'{{ projectsId }}'
RETURNING
occurrences
;
Creates a new occurrence.
INSERT INTO google.containeranalysis.occurrences (
data__build,
data__deployment,
data__name,
data__image,
data__updateTime,
data__upgrade,
data__remediation,
data__sbomReference,
data__secret,
data__createTime,
data__envelope,
data__advisoryPublishTime,
data__noteName,
data__discovery,
data__kind,
data__package,
data__compliance,
data__aiSkillAnalysis,
data__resourceUri,
data__attestation,
data__vulnerability,
data__dsseAttestation,
projectsId
)
SELECT
'{{ build }}',
'{{ deployment }}',
'{{ name }}',
'{{ image }}',
'{{ updateTime }}',
'{{ upgrade }}',
'{{ remediation }}',
'{{ sbomReference }}',
'{{ secret }}',
'{{ createTime }}',
'{{ envelope }}',
'{{ advisoryPublishTime }}',
'{{ noteName }}',
'{{ discovery }}',
'{{ kind }}',
'{{ package }}',
'{{ compliance }}',
'{{ aiSkillAnalysis }}',
'{{ resourceUri }}',
'{{ attestation }}',
'{{ vulnerability }}',
'{{ dsseAttestation }}',
'{{ projectsId }}'
RETURNING
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
;
# Description fields are for documentation purposes
- name: occurrences
props:
- name: projectsId
value: "{{ projectsId }}"
description: Required parameter for the occurrences resource.
- name: locationsId
value: "{{ locationsId }}"
description: Required parameter for the occurrences resource.
- name: build
description: |
Describes a verifiable build.
value:
intotoProvenance:
recipe:
environment: "{{ environment }}"
entryPoint: "{{ entryPoint }}"
definedInMaterial: "{{ definedInMaterial }}"
type: "{{ type }}"
arguments: "{{ arguments }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
arguments: {{ arguments }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
materials:
- "{{ materials }}"
builderConfig:
id: "{{ id }}"
intotoStatement:
provenance:
recipe:
environment: "{{ environment }}"
entryPoint: "{{ entryPoint }}"
definedInMaterial: "{{ definedInMaterial }}"
type: "{{ type }}"
arguments: "{{ arguments }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
arguments: {{ arguments }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
materials:
- "{{ materials }}"
builderConfig:
id: "{{ id }}"
slsaProvenanceZeroTwo:
builder:
id: "{{ id }}"
buildConfig: "{{ buildConfig }}"
metadata:
buildStartedOn: "{{ buildStartedOn }}"
completeness:
parameters: {{ parameters }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
buildInvocationId: "{{ buildInvocationId }}"
buildFinishedOn: "{{ buildFinishedOn }}"
materials:
- uri: "{{ uri }}"
digest: "{{ digest }}"
buildType: "{{ buildType }}"
invocation:
configSource:
entryPoint: "{{ entryPoint }}"
uri: "{{ uri }}"
digest: "{{ digest }}"
parameters: "{{ parameters }}"
environment: "{{ environment }}"
predicateType: "{{ predicateType }}"
_type: "{{ _type }}"
slsaProvenance:
builder:
id: "{{ id }}"
recipe:
definedInMaterial: "{{ definedInMaterial }}"
type: "{{ type }}"
arguments: "{{ arguments }}"
environment: "{{ environment }}"
entryPoint: "{{ entryPoint }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
environment: {{ environment }}
materials: {{ materials }}
arguments: {{ arguments }}
reproducible: {{ reproducible }}
buildInvocationId: "{{ buildInvocationId }}"
materials:
- uri: "{{ uri }}"
digest: "{{ digest }}"
subject:
- name: "{{ name }}"
digest: "{{ digest }}"
provenanceBytes: "{{ provenanceBytes }}"
inTotoSlsaProvenanceV1:
subject:
- name: "{{ name }}"
digest: "{{ digest }}"
predicateType: "{{ predicateType }}"
predicate:
buildDefinition:
buildType: "{{ buildType }}"
externalParameters: "{{ externalParameters }}"
internalParameters: "{{ internalParameters }}"
resolvedDependencies:
- mediaType: "{{ mediaType }}"
annotations: "{{ annotations }}"
content: "{{ content }}"
name: "{{ name }}"
uri: "{{ uri }}"
digest: "{{ digest }}"
downloadLocation: "{{ downloadLocation }}"
runDetails:
builder:
version: "{{ version }}"
builderDependencies: "{{ builderDependencies }}"
id: "{{ id }}"
metadata:
invocationId: "{{ invocationId }}"
finishedOn: "{{ finishedOn }}"
startedOn: "{{ startedOn }}"
byproducts:
- mediaType: "{{ mediaType }}"
annotations: "{{ annotations }}"
content: "{{ content }}"
name: "{{ name }}"
uri: "{{ uri }}"
digest: "{{ digest }}"
downloadLocation: "{{ downloadLocation }}"
_type: "{{ _type }}"
provenance:
commands:
- waitFor: "{{ waitFor }}"
name: "{{ name }}"
id: "{{ id }}"
args: "{{ args }}"
env: "{{ env }}"
dir: "{{ dir }}"
builtArtifacts:
- checksum: "{{ checksum }}"
names: "{{ names }}"
id: "{{ id }}"
createTime: "{{ createTime }}"
triggerId: "{{ triggerId }}"
creator: "{{ creator }}"
sourceProvenance:
artifactStorageSourceUri: "{{ artifactStorageSourceUri }}"
fileHashes: "{{ fileHashes }}"
context:
labels: "{{ labels }}"
git:
revisionId: "{{ revisionId }}"
url: "{{ url }}"
cloudRepo:
repoId: "{{ repoId }}"
revisionId: "{{ revisionId }}"
aliasContext: "{{ aliasContext }}"
gerrit:
hostUri: "{{ hostUri }}"
revisionId: "{{ revisionId }}"
aliasContext: "{{ aliasContext }}"
gerritProject: "{{ gerritProject }}"
additionalContexts:
- labels: "{{ labels }}"
git:
revisionId: "{{ revisionId }}"
url: "{{ url }}"
cloudRepo:
repoId: "{{ repoId }}"
revisionId: "{{ revisionId }}"
aliasContext: "{{ aliasContext }}"
gerrit:
hostUri: "{{ hostUri }}"
revisionId: "{{ revisionId }}"
aliasContext: "{{ aliasContext }}"
gerritProject: "{{ gerritProject }}"
builderVersion: "{{ builderVersion }}"
buildOptions: "{{ buildOptions }}"
logsUri: "{{ logsUri }}"
endTime: "{{ endTime }}"
projectId: "{{ projectId }}"
startTime: "{{ startTime }}"
id: "{{ id }}"
- name: deployment
description: |
Describes the deployment of an artifact on a runtime.
value:
deployTime: "{{ deployTime }}"
undeployTime: "{{ undeployTime }}"
config: "{{ config }}"
platform: "{{ platform }}"
resourceUri:
- "{{ resourceUri }}"
address: "{{ address }}"
userEmail: "{{ userEmail }}"
- name: name
value: "{{ name }}"
description: |
Output only. The name of the occurrence in the form of `projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]`.
- name: image
description: |
Describes how this resource derives from the basis in the associated note.
value:
distance: {{ distance }}
baseResourceUrl: "{{ baseResourceUrl }}"
fingerprint:
v1Name: "{{ v1Name }}"
v2Name: "{{ v2Name }}"
v2Blob:
- "{{ v2Blob }}"
layerInfo:
- arguments: "{{ arguments }}"
directive: "{{ directive }}"
- name: updateTime
value: "{{ updateTime }}"
description: |
Output only. The time this occurrence was last updated.
- name: upgrade
description: |
Describes an available package upgrade on the linked resource.
value:
windowsUpdate:
lastPublishedTimestamp: "{{ lastPublishedTimestamp }}"
title: "{{ title }}"
description: "{{ description }}"
categories:
- name: "{{ name }}"
categoryId: "{{ categoryId }}"
supportUrl: "{{ supportUrl }}"
identity:
revision: {{ revision }}
updateId: "{{ updateId }}"
kbArticleIds:
- "{{ kbArticleIds }}"
package: "{{ package }}"
parsedVersion:
epoch: {{ epoch }}
name: "{{ name }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
revision: "{{ revision }}"
fullName: "{{ fullName }}"
distribution:
cve:
- "{{ cve }}"
cpeUri: "{{ cpeUri }}"
classification: "{{ classification }}"
severity: "{{ severity }}"
- name: remediation
value: "{{ remediation }}"
description: |
A description of actions that can be taken to remedy the note.
- name: sbomReference
description: |
Describes a specific SBOM reference occurrences.
value:
payload:
predicateType: "{{ predicateType }}"
subject:
- name: "{{ name }}"
digest: "{{ digest }}"
predicate:
location: "{{ location }}"
digest: "{{ digest }}"
mimeType: "{{ mimeType }}"
referrerId: "{{ referrerId }}"
_type: "{{ _type }}"
payloadType: "{{ payloadType }}"
signatures:
- sig: "{{ sig }}"
keyid: "{{ keyid }}"
- name: secret
description: |
Describes a secret.
value:
kind: "{{ kind }}"
locations:
- fileLocation:
lineNumber: {{ lineNumber }}
filePath: "{{ filePath }}"
layerDetails:
index: {{ index }}
command: "{{ command }}"
diffId: "{{ diffId }}"
chainId: "{{ chainId }}"
baseImages:
- layerCount: {{ layerCount }}
registry: "{{ registry }}"
name: "{{ name }}"
repository: "{{ repository }}"
statuses:
- message: "{{ message }}"
status: "{{ status }}"
updateTime: "{{ updateTime }}"
- name: createTime
value: "{{ createTime }}"
description: |
Output only. The time this occurrence was created.
- name: envelope
description: |
https://github.com/secure-systems-lab/dsse
value:
signatures:
- sig: "{{ sig }}"
keyid: "{{ keyid }}"
payload: "{{ payload }}"
payloadType: "{{ payloadType }}"
- name: advisoryPublishTime
value: "{{ advisoryPublishTime }}"
description: |
The time this advisory was published by the source.
- name: noteName
value: "{{ noteName }}"
description: |
Required. Immutable. The analysis note associated with this occurrence, in the form of `projects/[PROVIDER_ID]/notes/[NOTE_ID]`. This field can be used as a filter in list requests.
- name: discovery
description: |
Describes when a resource was discovered.
value:
lastVulnerabilityUpdateTime: "{{ lastVulnerabilityUpdateTime }}"
analysisStatus: "{{ analysisStatus }}"
cpe: "{{ cpe }}"
archiveTime: "{{ archiveTime }}"
analysisCompleted:
analysisType:
- "{{ analysisType }}"
continuousAnalysis: "{{ continuousAnalysis }}"
files:
- name: "{{ name }}"
digest: "{{ digest }}"
analysisStatusError:
message: "{{ message }}"
code: {{ code }}
details: "{{ details }}"
lastScanTime: "{{ lastScanTime }}"
sbomStatus:
sbomState: "{{ sbomState }}"
error: "{{ error }}"
analysisError:
- message: "{{ message }}"
code: {{ code }}
details: "{{ details }}"
- name: kind
value: "{{ kind }}"
description: |
Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests.
valid_values: ['NOTE_KIND_UNSPECIFIED', 'VULNERABILITY', 'BUILD', 'IMAGE', 'PACKAGE', 'DEPLOYMENT', 'DISCOVERY', 'ATTESTATION', 'UPGRADE', 'COMPLIANCE', 'DSSE_ATTESTATION', 'VULNERABILITY_ASSESSMENT', 'SBOM_REFERENCE', 'SECRET', 'AI_SKILL_ANALYSIS']
- name: package
description: |
Describes the installation of a package on the linked resource.
value:
location:
- cpeUri: "{{ cpeUri }}"
path: "{{ path }}"
version:
epoch: {{ epoch }}
name: "{{ name }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
revision: "{{ revision }}"
fullName: "{{ fullName }}"
architecture: "{{ architecture }}"
packageType: "{{ packageType }}"
license:
expression: "{{ expression }}"
comments: "{{ comments }}"
name: "{{ name }}"
version:
epoch: {{ epoch }}
name: "{{ name }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
revision: "{{ revision }}"
fullName: "{{ fullName }}"
cpeUri: "{{ cpeUri }}"
- name: compliance
description: |
Describes a compliance violation on a linked resource.
value:
nonComplianceReason: "{{ nonComplianceReason }}"
nonCompliantFiles:
- path: "{{ path }}"
reason: "{{ reason }}"
displayCommand: "{{ displayCommand }}"
version:
benchmarkDocument: "{{ benchmarkDocument }}"
version: "{{ version }}"
cpeUri: "{{ cpeUri }}"
- name: aiSkillAnalysis
description: |
Describes an AI skill analysis.
value:
maxSeverity: "{{ maxSeverity }}"
skillName: "{{ skillName }}"
findings:
- scanner: "{{ scanner }}"
location:
filePath: "{{ filePath }}"
lineNumber: "{{ lineNumber }}"
severity: "{{ severity }}"
category: "{{ category }}"
details: "{{ details }}"
- name: resourceUri
value: "{{ resourceUri }}"
description: |
Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, `https://gcr.io/project/image@sha256:123abc` for a Docker image.
- name: attestation
description: |
Describes an attestation of an artifact.
value:
serializedPayload: "{{ serializedPayload }}"
signatures:
- publicKeyId: "{{ publicKeyId }}"
signature: "{{ signature }}"
jwts:
- compactJwt: "{{ compactJwt }}"
- name: vulnerability
description: |
Describes a security vulnerability.
value:
risk:
cisaKev:
knownRansomwareCampaignUse: "{{ knownRansomwareCampaignUse }}"
epss:
score: {{ score }}
percentile: {{ percentile }}
fixAvailable: {{ fixAvailable }}
severity: "{{ severity }}"
packageIssue:
- fixedCpeUri: "{{ fixedCpeUri }}"
fixedVersion:
epoch: {{ epoch }}
name: "{{ name }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
revision: "{{ revision }}"
fullName: "{{ fullName }}"
affectedPackage: "{{ affectedPackage }}"
packageType: "{{ packageType }}"
affectedCpeUri: "{{ affectedCpeUri }}"
fixAvailable: {{ fixAvailable }}
fixedPackage: "{{ fixedPackage }}"
fileLocation: "{{ fileLocation }}"
affectedVersion:
epoch: {{ epoch }}
name: "{{ name }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
revision: "{{ revision }}"
fullName: "{{ fullName }}"
effectiveSeverity: "{{ effectiveSeverity }}"
relatedUrls:
- url: "{{ url }}"
label: "{{ label }}"
vexAssessment:
vulnerabilityId: "{{ vulnerabilityId }}"
relatedUris:
- url: "{{ url }}"
label: "{{ label }}"
noteName: "{{ noteName }}"
remediations:
- details: "{{ details }}"
remediationType: "{{ remediationType }}"
remediationUri:
url: "{{ url }}"
label: "{{ label }}"
impacts:
- "{{ impacts }}"
justification:
justificationType: "{{ justificationType }}"
details: "{{ details }}"
cve: "{{ cve }}"
state: "{{ state }}"
cvssV4:
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
attackVector: "{{ attackVector }}"
impactScore: {{ impactScore }}
authentication: "{{ authentication }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
baseScore: {{ baseScore }}
integrityImpact: "{{ integrityImpact }}"
availabilityImpact: "{{ availabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
scope: "{{ scope }}"
attackRequirements: "{{ attackRequirements }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
exploitabilityScore: {{ exploitabilityScore }}
privilegesRequired: "{{ privilegesRequired }}"
attackComplexity: "{{ attackComplexity }}"
confidentialityImpact: "{{ confidentialityImpact }}"
cvssVersion: "{{ cvssVersion }}"
extraDetails: "{{ extraDetails }}"
type: "{{ type }}"
shortDescription: "{{ shortDescription }}"
longDescription: "{{ longDescription }}"
cvssV2:
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
attackVector: "{{ attackVector }}"
impactScore: {{ impactScore }}
authentication: "{{ authentication }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
baseScore: {{ baseScore }}
integrityImpact: "{{ integrityImpact }}"
availabilityImpact: "{{ availabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
scope: "{{ scope }}"
attackRequirements: "{{ attackRequirements }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
exploitabilityScore: {{ exploitabilityScore }}
privilegesRequired: "{{ privilegesRequired }}"
attackComplexity: "{{ attackComplexity }}"
confidentialityImpact: "{{ confidentialityImpact }}"
cvssScore: {{ cvssScore }}
cvssv3:
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
attackVector: "{{ attackVector }}"
impactScore: {{ impactScore }}
authentication: "{{ authentication }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
baseScore: {{ baseScore }}
integrityImpact: "{{ integrityImpact }}"
availabilityImpact: "{{ availabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
scope: "{{ scope }}"
attackRequirements: "{{ attackRequirements }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
exploitabilityScore: {{ exploitabilityScore }}
privilegesRequired: "{{ privilegesRequired }}"
attackComplexity: "{{ attackComplexity }}"
confidentialityImpact: "{{ confidentialityImpact }}"
effectiveSeverity: "{{ effectiveSeverity }}"
- name: dsseAttestation
description: |
Describes an attestation of an artifact using dsse.
value:
envelope:
signatures:
- sig: "{{ sig }}"
keyid: "{{ keyid }}"
payload: "{{ payload }}"
payloadType: "{{ payloadType }}"
statement:
provenance:
recipe:
environment: "{{ environment }}"
entryPoint: "{{ entryPoint }}"
definedInMaterial: "{{ definedInMaterial }}"
type: "{{ type }}"
arguments: "{{ arguments }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
arguments: {{ arguments }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
materials:
- "{{ materials }}"
builderConfig:
id: "{{ id }}"
slsaProvenanceZeroTwo:
builder:
id: "{{ id }}"
buildConfig: "{{ buildConfig }}"
metadata:
buildStartedOn: "{{ buildStartedOn }}"
completeness:
parameters: {{ parameters }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
buildInvocationId: "{{ buildInvocationId }}"
buildFinishedOn: "{{ buildFinishedOn }}"
materials:
- uri: "{{ uri }}"
digest: "{{ digest }}"
buildType: "{{ buildType }}"
invocation:
configSource:
entryPoint: "{{ entryPoint }}"
uri: "{{ uri }}"
digest: "{{ digest }}"
parameters: "{{ parameters }}"
environment: "{{ environment }}"
predicateType: "{{ predicateType }}"
_type: "{{ _type }}"
slsaProvenance:
builder:
id: "{{ id }}"
recipe:
definedInMaterial: "{{ definedInMaterial }}"
type: "{{ type }}"
arguments: "{{ arguments }}"
environment: "{{ environment }}"
entryPoint: "{{ entryPoint }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
environment: {{ environment }}
materials: {{ materials }}
arguments: {{ arguments }}
reproducible: {{ reproducible }}
buildInvocationId: "{{ buildInvocationId }}"
materials:
- uri: "{{ uri }}"
digest: "{{ digest }}"
subject:
- name: "{{ name }}"
digest: "{{ digest }}"
- name: occurrences
description: |
Required. The occurrences to create. Max allowed length is 1000.
value:
- build:
intotoProvenance:
recipe:
environment: "{{ environment }}"
entryPoint: "{{ entryPoint }}"
definedInMaterial: "{{ definedInMaterial }}"
type: "{{ type }}"
arguments: "{{ arguments }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
arguments: {{ arguments }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
materials:
- "{{ materials }}"
builderConfig:
id: "{{ id }}"
intotoStatement:
provenance:
recipe:
environment: "{{ environment }}"
entryPoint: "{{ entryPoint }}"
definedInMaterial: "{{ definedInMaterial }}"
type: "{{ type }}"
arguments: "{{ arguments }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
materials:
- "{{ materials }}"
builderConfig:
id: "{{ id }}"
slsaProvenanceZeroTwo:
builder:
id: "{{ id }}"
buildConfig: "{{ buildConfig }}"
metadata:
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
buildInvocationId: "{{ buildInvocationId }}"
buildFinishedOn: "{{ buildFinishedOn }}"
materials:
- uri: "{{ uri }}"
digest: "{{ digest }}"
buildType: "{{ buildType }}"
invocation:
configSource: "{{ configSource }}"
parameters: "{{ parameters }}"
environment: "{{ environment }}"
predicateType: "{{ predicateType }}"
_type: "{{ _type }}"
slsaProvenance:
builder:
id: "{{ id }}"
recipe:
definedInMaterial: "{{ definedInMaterial }}"
type: "{{ type }}"
arguments: "{{ arguments }}"
environment: "{{ environment }}"
entryPoint: "{{ entryPoint }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
buildInvocationId: "{{ buildInvocationId }}"
materials:
- uri: "{{ uri }}"
digest: "{{ digest }}"
subject:
- name: "{{ name }}"
digest: "{{ digest }}"
provenanceBytes: "{{ provenanceBytes }}"
inTotoSlsaProvenanceV1:
subject:
- name: "{{ name }}"
digest: "{{ digest }}"
predicateType: "{{ predicateType }}"
predicate:
buildDefinition:
buildType: "{{ buildType }}"
externalParameters: "{{ externalParameters }}"
internalParameters: "{{ internalParameters }}"
resolvedDependencies: "{{ resolvedDependencies }}"
runDetails:
builder: "{{ builder }}"
metadata: "{{ metadata }}"
byproducts: "{{ byproducts }}"
_type: "{{ _type }}"
provenance:
commands:
- waitFor: "{{ waitFor }}"
name: "{{ name }}"
id: "{{ id }}"
args: "{{ args }}"
env: "{{ env }}"
dir: "{{ dir }}"
builtArtifacts:
- checksum: "{{ checksum }}"
names: "{{ names }}"
id: "{{ id }}"
createTime: "{{ createTime }}"
triggerId: "{{ triggerId }}"
creator: "{{ creator }}"
sourceProvenance:
artifactStorageSourceUri: "{{ artifactStorageSourceUri }}"
fileHashes: "{{ fileHashes }}"
context:
labels: "{{ labels }}"
git: "{{ git }}"
cloudRepo: "{{ cloudRepo }}"
gerrit: "{{ gerrit }}"
additionalContexts:
- labels: "{{ labels }}"
git:
revisionId: "{{ revisionId }}"
url: "{{ url }}"
cloudRepo:
repoId: "{{ repoId }}"
revisionId: "{{ revisionId }}"
aliasContext: "{{ aliasContext }}"
gerrit:
hostUri: "{{ hostUri }}"
revisionId: "{{ revisionId }}"
aliasContext: "{{ aliasContext }}"
gerritProject: "{{ gerritProject }}"
builderVersion: "{{ builderVersion }}"
buildOptions: "{{ buildOptions }}"
logsUri: "{{ logsUri }}"
endTime: "{{ endTime }}"
projectId: "{{ projectId }}"
startTime: "{{ startTime }}"
id: "{{ id }}"
deployment:
deployTime: "{{ deployTime }}"
undeployTime: "{{ undeployTime }}"
config: "{{ config }}"
platform: "{{ platform }}"
resourceUri:
- "{{ resourceUri }}"
address: "{{ address }}"
userEmail: "{{ userEmail }}"
name: "{{ name }}"
image:
distance: {{ distance }}
baseResourceUrl: "{{ baseResourceUrl }}"
fingerprint:
v1Name: "{{ v1Name }}"
v2Name: "{{ v2Name }}"
v2Blob:
- "{{ v2Blob }}"
layerInfo:
- arguments: "{{ arguments }}"
directive: "{{ directive }}"
updateTime: "{{ updateTime }}"
upgrade:
windowsUpdate:
lastPublishedTimestamp: "{{ lastPublishedTimestamp }}"
title: "{{ title }}"
description: "{{ description }}"
categories:
- name: "{{ name }}"
categoryId: "{{ categoryId }}"
supportUrl: "{{ supportUrl }}"
identity:
revision: {{ revision }}
updateId: "{{ updateId }}"
kbArticleIds:
- "{{ kbArticleIds }}"
package: "{{ package }}"
parsedVersion:
epoch: {{ epoch }}
name: "{{ name }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
revision: "{{ revision }}"
fullName: "{{ fullName }}"
distribution:
cve:
- "{{ cve }}"
cpeUri: "{{ cpeUri }}"
classification: "{{ classification }}"
severity: "{{ severity }}"
remediation: "{{ remediation }}"
sbomReference:
payload:
predicateType: "{{ predicateType }}"
subject:
- name: "{{ name }}"
digest: "{{ digest }}"
predicate:
location: "{{ location }}"
digest: "{{ digest }}"
mimeType: "{{ mimeType }}"
referrerId: "{{ referrerId }}"
_type: "{{ _type }}"
payloadType: "{{ payloadType }}"
signatures:
- sig: "{{ sig }}"
keyid: "{{ keyid }}"
secret:
kind: "{{ kind }}"
locations:
- fileLocation:
lineNumber: {{ lineNumber }}
filePath: "{{ filePath }}"
layerDetails:
index: {{ index }}
command: "{{ command }}"
diffId: "{{ diffId }}"
chainId: "{{ chainId }}"
baseImages: "{{ baseImages }}"
statuses:
- message: "{{ message }}"
status: "{{ status }}"
updateTime: "{{ updateTime }}"
createTime: "{{ createTime }}"
envelope:
signatures:
- sig: "{{ sig }}"
keyid: "{{ keyid }}"
payload: "{{ payload }}"
payloadType: "{{ payloadType }}"
advisoryPublishTime: "{{ advisoryPublishTime }}"
noteName: "{{ noteName }}"
discovery:
lastVulnerabilityUpdateTime: "{{ lastVulnerabilityUpdateTime }}"
analysisStatus: "{{ analysisStatus }}"
cpe: "{{ cpe }}"
archiveTime: "{{ archiveTime }}"
analysisCompleted:
analysisType:
- "{{ analysisType }}"
continuousAnalysis: "{{ continuousAnalysis }}"
files:
- name: "{{ name }}"
digest: "{{ digest }}"
analysisStatusError:
message: "{{ message }}"
code: {{ code }}
details: "{{ details }}"
lastScanTime: "{{ lastScanTime }}"
sbomStatus:
sbomState: "{{ sbomState }}"
error: "{{ error }}"
analysisError:
- message: "{{ message }}"
code: {{ code }}
details: "{{ details }}"
kind: "{{ kind }}"
package:
location:
- cpeUri: "{{ cpeUri }}"
path: "{{ path }}"
version:
epoch: {{ epoch }}
name: "{{ name }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
revision: "{{ revision }}"
fullName: "{{ fullName }}"
architecture: "{{ architecture }}"
packageType: "{{ packageType }}"
license:
expression: "{{ expression }}"
comments: "{{ comments }}"
name: "{{ name }}"
version:
epoch: {{ epoch }}
name: "{{ name }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
revision: "{{ revision }}"
fullName: "{{ fullName }}"
cpeUri: "{{ cpeUri }}"
compliance:
nonComplianceReason: "{{ nonComplianceReason }}"
nonCompliantFiles:
- path: "{{ path }}"
reason: "{{ reason }}"
displayCommand: "{{ displayCommand }}"
version:
benchmarkDocument: "{{ benchmarkDocument }}"
version: "{{ version }}"
cpeUri: "{{ cpeUri }}"
aiSkillAnalysis:
maxSeverity: "{{ maxSeverity }}"
skillName: "{{ skillName }}"
findings:
- scanner: "{{ scanner }}"
location:
filePath: "{{ filePath }}"
lineNumber: "{{ lineNumber }}"
severity: "{{ severity }}"
category: "{{ category }}"
details: "{{ details }}"
resourceUri: "{{ resourceUri }}"
attestation:
serializedPayload: "{{ serializedPayload }}"
signatures:
- publicKeyId: "{{ publicKeyId }}"
signature: "{{ signature }}"
jwts:
- compactJwt: "{{ compactJwt }}"
vulnerability:
risk:
cisaKev:
knownRansomwareCampaignUse: "{{ knownRansomwareCampaignUse }}"
epss:
score: {{ score }}
percentile: {{ percentile }}
fixAvailable: {{ fixAvailable }}
severity: "{{ severity }}"
packageIssue:
- fixedCpeUri: "{{ fixedCpeUri }}"
fixedVersion:
epoch: {{ epoch }}
name: "{{ name }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
revision: "{{ revision }}"
fullName: "{{ fullName }}"
affectedPackage: "{{ affectedPackage }}"
packageType: "{{ packageType }}"
affectedCpeUri: "{{ affectedCpeUri }}"
fixAvailable: {{ fixAvailable }}
fixedPackage: "{{ fixedPackage }}"
fileLocation: "{{ fileLocation }}"
affectedVersion:
epoch: {{ epoch }}
name: "{{ name }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
revision: "{{ revision }}"
fullName: "{{ fullName }}"
effectiveSeverity: "{{ effectiveSeverity }}"
relatedUrls:
- url: "{{ url }}"
label: "{{ label }}"
vexAssessment:
vulnerabilityId: "{{ vulnerabilityId }}"
relatedUris:
- url: "{{ url }}"
label: "{{ label }}"
noteName: "{{ noteName }}"
remediations:
- details: "{{ details }}"
remediationType: "{{ remediationType }}"
remediationUri:
url: "{{ url }}"
label: "{{ label }}"
impacts:
- "{{ impacts }}"
justification:
justificationType: "{{ justificationType }}"
details: "{{ details }}"
cve: "{{ cve }}"
state: "{{ state }}"
cvssV4:
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
attackVector: "{{ attackVector }}"
impactScore: {{ impactScore }}
authentication: "{{ authentication }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
baseScore: {{ baseScore }}
integrityImpact: "{{ integrityImpact }}"
availabilityImpact: "{{ availabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
scope: "{{ scope }}"
attackRequirements: "{{ attackRequirements }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
exploitabilityScore: {{ exploitabilityScore }}
privilegesRequired: "{{ privilegesRequired }}"
attackComplexity: "{{ attackComplexity }}"
confidentialityImpact: "{{ confidentialityImpact }}"
cvssVersion: "{{ cvssVersion }}"
extraDetails: "{{ extraDetails }}"
type: "{{ type }}"
shortDescription: "{{ shortDescription }}"
longDescription: "{{ longDescription }}"
cvssV2:
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
attackVector: "{{ attackVector }}"
impactScore: {{ impactScore }}
authentication: "{{ authentication }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
baseScore: {{ baseScore }}
integrityImpact: "{{ integrityImpact }}"
availabilityImpact: "{{ availabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
scope: "{{ scope }}"
attackRequirements: "{{ attackRequirements }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
exploitabilityScore: {{ exploitabilityScore }}
privilegesRequired: "{{ privilegesRequired }}"
attackComplexity: "{{ attackComplexity }}"
confidentialityImpact: "{{ confidentialityImpact }}"
cvssScore: {{ cvssScore }}
cvssv3:
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
attackVector: "{{ attackVector }}"
impactScore: {{ impactScore }}
authentication: "{{ authentication }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
baseScore: {{ baseScore }}
integrityImpact: "{{ integrityImpact }}"
availabilityImpact: "{{ availabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
scope: "{{ scope }}"
attackRequirements: "{{ attackRequirements }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
exploitabilityScore: {{ exploitabilityScore }}
privilegesRequired: "{{ privilegesRequired }}"
attackComplexity: "{{ attackComplexity }}"
confidentialityImpact: "{{ confidentialityImpact }}"
effectiveSeverity: "{{ effectiveSeverity }}"
dsseAttestation:
envelope:
signatures:
- sig: "{{ sig }}"
keyid: "{{ keyid }}"
payload: "{{ payload }}"
payloadType: "{{ payloadType }}"
statement:
provenance:
recipe:
environment: "{{ environment }}"
entryPoint: "{{ entryPoint }}"
definedInMaterial: "{{ definedInMaterial }}"
type: "{{ type }}"
arguments: "{{ arguments }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
materials:
- "{{ materials }}"
builderConfig:
id: "{{ id }}"
slsaProvenanceZeroTwo:
builder:
id: "{{ id }}"
buildConfig: "{{ buildConfig }}"
metadata:
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
buildInvocationId: "{{ buildInvocationId }}"
buildFinishedOn: "{{ buildFinishedOn }}"
materials:
- uri: "{{ uri }}"
digest: "{{ digest }}"
buildType: "{{ buildType }}"
invocation:
configSource: "{{ configSource }}"
parameters: "{{ parameters }}"
environment: "{{ environment }}"
predicateType: "{{ predicateType }}"
_type: "{{ _type }}"
slsaProvenance:
builder:
id: "{{ id }}"
recipe:
definedInMaterial: "{{ definedInMaterial }}"
type: "{{ type }}"
arguments: "{{ arguments }}"
environment: "{{ environment }}"
entryPoint: "{{ entryPoint }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
buildInvocationId: "{{ buildInvocationId }}"
materials:
- uri: "{{ uri }}"
digest: "{{ digest }}"
subject:
- name: "{{ name }}"
digest: "{{ digest }}"
UPDATE examples
- projects_locations_occurrences_patch
- projects_occurrences_patch
Updates the specified occurrence.
UPDATE google.containeranalysis.occurrences
SET
data__build = '{{ build }}',
data__deployment = '{{ deployment }}',
data__name = '{{ name }}',
data__image = '{{ image }}',
data__updateTime = '{{ updateTime }}',
data__upgrade = '{{ upgrade }}',
data__remediation = '{{ remediation }}',
data__sbomReference = '{{ sbomReference }}',
data__secret = '{{ secret }}',
data__createTime = '{{ createTime }}',
data__envelope = '{{ envelope }}',
data__advisoryPublishTime = '{{ advisoryPublishTime }}',
data__noteName = '{{ noteName }}',
data__discovery = '{{ discovery }}',
data__kind = '{{ kind }}',
data__package = '{{ package }}',
data__compliance = '{{ compliance }}',
data__aiSkillAnalysis = '{{ aiSkillAnalysis }}',
data__resourceUri = '{{ resourceUri }}',
data__attestation = '{{ attestation }}',
data__vulnerability = '{{ vulnerability }}',
data__dsseAttestation = '{{ dsseAttestation }}'
WHERE
projectsId = '{{ projectsId }}' --required
AND locationsId = '{{ locationsId }}' --required
AND occurrencesId = '{{ occurrencesId }}' --required
AND updateMask = '{{ updateMask}}'
RETURNING
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability;
Updates the specified occurrence.
UPDATE google.containeranalysis.occurrences
SET
data__build = '{{ build }}',
data__deployment = '{{ deployment }}',
data__name = '{{ name }}',
data__image = '{{ image }}',
data__updateTime = '{{ updateTime }}',
data__upgrade = '{{ upgrade }}',
data__remediation = '{{ remediation }}',
data__sbomReference = '{{ sbomReference }}',
data__secret = '{{ secret }}',
data__createTime = '{{ createTime }}',
data__envelope = '{{ envelope }}',
data__advisoryPublishTime = '{{ advisoryPublishTime }}',
data__noteName = '{{ noteName }}',
data__discovery = '{{ discovery }}',
data__kind = '{{ kind }}',
data__package = '{{ package }}',
data__compliance = '{{ compliance }}',
data__aiSkillAnalysis = '{{ aiSkillAnalysis }}',
data__resourceUri = '{{ resourceUri }}',
data__attestation = '{{ attestation }}',
data__vulnerability = '{{ vulnerability }}',
data__dsseAttestation = '{{ dsseAttestation }}'
WHERE
projectsId = '{{ projectsId }}' --required
AND occurrencesId = '{{ occurrencesId }}' --required
AND updateMask = '{{ updateMask}}'
RETURNING
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability;
DELETE examples
- projects_locations_occurrences_delete
- projects_occurrences_delete
Deletes the specified occurrence. For example, use this method to delete an occurrence when the occurrence is no longer applicable for the given resource.
DELETE FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' --required
AND locationsId = '{{ locationsId }}' --required
AND occurrencesId = '{{ occurrencesId }}' --required
;
Deletes the specified occurrence. For example, use this method to delete an occurrence when the occurrence is no longer applicable for the given resource.
DELETE FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' --required
AND occurrencesId = '{{ occurrencesId }}' --required
;