occurrences
Creates, updates, deletes, gets or lists an occurrences resource.
Overview
| Name | occurrences |
| Type | Resource |
| Id | google.containeranalysis.occurrences |
Fields
The following fields are returned by SELECT queries:
- projects_locations_notes_occurrences_list
- projects_locations_occurrences_get
- projects_locations_occurrences_list
- projects_notes_occurrences_list
- projects_occurrences_get
- projects_occurrences_list
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The name of the occurrence in the form of projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]. |
advisoryPublishTime | string (google-datetime) | The time this advisory was published by the source. |
aiSkillAnalysis | object | Describes an AI skill analysis. (id: AISkillAnalysisOccurrence) |
attestation | object | Describes an attestation of an artifact. (id: AttestationOccurrence) |
build | object | Describes a verifiable build. (id: BuildOccurrence) |
compliance | object | Describes a compliance violation on a linked resource. (id: ComplianceOccurrence) |
createTime | string (google-datetime) | Output only. The time this occurrence was created. |
deployment | object | Describes the deployment of an artifact on a runtime. (id: DeploymentOccurrence) |
discovery | object | Describes when a resource was discovered. (id: DiscoveryOccurrence) |
dsseAttestation | object | Describes an attestation of an artifact using dsse. (id: DSSEAttestationOccurrence) |
envelope | object | https://github.com/secure-systems-lab/dsse (id: Envelope) |
image | object | Describes how this resource derives from the basis in the associated note. (id: ImageOccurrence) |
kind | string | Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests. (NOTE_KIND_UNSPECIFIED, VULNERABILITY, BUILD, IMAGE, PACKAGE, DEPLOYMENT, DISCOVERY, ATTESTATION, UPGRADE, COMPLIANCE, DSSE_ATTESTATION, VULNERABILITY_ASSESSMENT, SBOM_REFERENCE, SECRET, AI_SKILL_ANALYSIS) |
noteName | string | Required. Immutable. The analysis note associated with this occurrence, in the form of projects/[PROVIDER_ID]/notes/[NOTE_ID]. This field can be used as a filter in list requests. |
package | object | Describes the installation of a package on the linked resource. (id: PackageOccurrence) |
remediation | string | A description of actions that can be taken to remedy the note. |
resourceUri | string | Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, https://gcr.io/project/image@sha256:123abc for a Docker image. |
sbomReference | object | Describes a specific SBOM reference occurrences. (id: SBOMReferenceOccurrence) |
secret | object | Describes a secret. (id: SecretOccurrence) |
updateTime | string (google-datetime) | Output only. The time this occurrence was last updated. |
upgrade | object | Describes an available package upgrade on the linked resource. (id: UpgradeOccurrence) |
vulnerability | object | Describes a security vulnerability. (id: VulnerabilityOccurrence) |
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The name of the occurrence in the form of projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]. |
advisoryPublishTime | string (google-datetime) | The time this advisory was published by the source. |
aiSkillAnalysis | object | Describes an AI skill analysis. (id: AISkillAnalysisOccurrence) |
attestation | object | Describes an attestation of an artifact. (id: AttestationOccurrence) |
build | object | Describes a verifiable build. (id: BuildOccurrence) |
compliance | object | Describes a compliance violation on a linked resource. (id: ComplianceOccurrence) |
createTime | string (google-datetime) | Output only. The time this occurrence was created. |
deployment | object | Describes the deployment of an artifact on a runtime. (id: DeploymentOccurrence) |
discovery | object | Describes when a resource was discovered. (id: DiscoveryOccurrence) |
dsseAttestation | object | Describes an attestation of an artifact using dsse. (id: DSSEAttestationOccurrence) |
envelope | object | https://github.com/secure-systems-lab/dsse (id: Envelope) |
image | object | Describes how this resource derives from the basis in the associated note. (id: ImageOccurrence) |
kind | string | Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests. (NOTE_KIND_UNSPECIFIED, VULNERABILITY, BUILD, IMAGE, PACKAGE, DEPLOYMENT, DISCOVERY, ATTESTATION, UPGRADE, COMPLIANCE, DSSE_ATTESTATION, VULNERABILITY_ASSESSMENT, SBOM_REFERENCE, SECRET, AI_SKILL_ANALYSIS) |
noteName | string | Required. Immutable. The analysis note associated with this occurrence, in the form of projects/[PROVIDER_ID]/notes/[NOTE_ID]. This field can be used as a filter in list requests. |
package | object | Describes the installation of a package on the linked resource. (id: PackageOccurrence) |
remediation | string | A description of actions that can be taken to remedy the note. |
resourceUri | string | Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, https://gcr.io/project/image@sha256:123abc for a Docker image. |
sbomReference | object | Describes a specific SBOM reference occurrences. (id: SBOMReferenceOccurrence) |
secret | object | Describes a secret. (id: SecretOccurrence) |
updateTime | string (google-datetime) | Output only. The time this occurrence was last updated. |
upgrade | object | Describes an available package upgrade on the linked resource. (id: UpgradeOccurrence) |
vulnerability | object | Describes a security vulnerability. (id: VulnerabilityOccurrence) |
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The name of the occurrence in the form of projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]. |
advisoryPublishTime | string (google-datetime) | The time this advisory was published by the source. |
aiSkillAnalysis | object | Describes an AI skill analysis. (id: AISkillAnalysisOccurrence) |
attestation | object | Describes an attestation of an artifact. (id: AttestationOccurrence) |
build | object | Describes a verifiable build. (id: BuildOccurrence) |
compliance | object | Describes a compliance violation on a linked resource. (id: ComplianceOccurrence) |
createTime | string (google-datetime) | Output only. The time this occurrence was created. |
deployment | object | Describes the deployment of an artifact on a runtime. (id: DeploymentOccurrence) |
discovery | object | Describes when a resource was discovered. (id: DiscoveryOccurrence) |
dsseAttestation | object | Describes an attestation of an artifact using dsse. (id: DSSEAttestationOccurrence) |
envelope | object | https://github.com/secure-systems-lab/dsse (id: Envelope) |
image | object | Describes how this resource derives from the basis in the associated note. (id: ImageOccurrence) |
kind | string | Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests. (NOTE_KIND_UNSPECIFIED, VULNERABILITY, BUILD, IMAGE, PACKAGE, DEPLOYMENT, DISCOVERY, ATTESTATION, UPGRADE, COMPLIANCE, DSSE_ATTESTATION, VULNERABILITY_ASSESSMENT, SBOM_REFERENCE, SECRET, AI_SKILL_ANALYSIS) |
noteName | string | Required. Immutable. The analysis note associated with this occurrence, in the form of projects/[PROVIDER_ID]/notes/[NOTE_ID]. This field can be used as a filter in list requests. |
package | object | Describes the installation of a package on the linked resource. (id: PackageOccurrence) |
remediation | string | A description of actions that can be taken to remedy the note. |
resourceUri | string | Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, https://gcr.io/project/image@sha256:123abc for a Docker image. |
sbomReference | object | Describes a specific SBOM reference occurrences. (id: SBOMReferenceOccurrence) |
secret | object | Describes a secret. (id: SecretOccurrence) |
updateTime | string (google-datetime) | Output only. The time this occurrence was last updated. |
upgrade | object | Describes an available package upgrade on the linked resource. (id: UpgradeOccurrence) |
vulnerability | object | Describes a security vulnerability. (id: VulnerabilityOccurrence) |
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The name of the occurrence in the form of projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]. |
advisoryPublishTime | string (google-datetime) | The time this advisory was published by the source. |
aiSkillAnalysis | object | Describes an AI skill analysis. (id: AISkillAnalysisOccurrence) |
attestation | object | Describes an attestation of an artifact. (id: AttestationOccurrence) |
build | object | Describes a verifiable build. (id: BuildOccurrence) |
compliance | object | Describes a compliance violation on a linked resource. (id: ComplianceOccurrence) |
createTime | string (google-datetime) | Output only. The time this occurrence was created. |
deployment | object | Describes the deployment of an artifact on a runtime. (id: DeploymentOccurrence) |
discovery | object | Describes when a resource was discovered. (id: DiscoveryOccurrence) |
dsseAttestation | object | Describes an attestation of an artifact using dsse. (id: DSSEAttestationOccurrence) |
envelope | object | https://github.com/secure-systems-lab/dsse (id: Envelope) |
image | object | Describes how this resource derives from the basis in the associated note. (id: ImageOccurrence) |
kind | string | Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests. (NOTE_KIND_UNSPECIFIED, VULNERABILITY, BUILD, IMAGE, PACKAGE, DEPLOYMENT, DISCOVERY, ATTESTATION, UPGRADE, COMPLIANCE, DSSE_ATTESTATION, VULNERABILITY_ASSESSMENT, SBOM_REFERENCE, SECRET, AI_SKILL_ANALYSIS) |
noteName | string | Required. Immutable. The analysis note associated with this occurrence, in the form of projects/[PROVIDER_ID]/notes/[NOTE_ID]. This field can be used as a filter in list requests. |
package | object | Describes the installation of a package on the linked resource. (id: PackageOccurrence) |
remediation | string | A description of actions that can be taken to remedy the note. |
resourceUri | string | Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, https://gcr.io/project/image@sha256:123abc for a Docker image. |
sbomReference | object | Describes a specific SBOM reference occurrences. (id: SBOMReferenceOccurrence) |
secret | object | Describes a secret. (id: SecretOccurrence) |
updateTime | string (google-datetime) | Output only. The time this occurrence was last updated. |
upgrade | object | Describes an available package upgrade on the linked resource. (id: UpgradeOccurrence) |
vulnerability | object | Describes a security vulnerability. (id: VulnerabilityOccurrence) |
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The name of the occurrence in the form of projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]. |
advisoryPublishTime | string (google-datetime) | The time this advisory was published by the source. |
aiSkillAnalysis | object | Describes an AI skill analysis. (id: AISkillAnalysisOccurrence) |
attestation | object | Describes an attestation of an artifact. (id: AttestationOccurrence) |
build | object | Describes a verifiable build. (id: BuildOccurrence) |
compliance | object | Describes a compliance violation on a linked resource. (id: ComplianceOccurrence) |
createTime | string (google-datetime) | Output only. The time this occurrence was created. |
deployment | object | Describes the deployment of an artifact on a runtime. (id: DeploymentOccurrence) |
discovery | object | Describes when a resource was discovered. (id: DiscoveryOccurrence) |
dsseAttestation | object | Describes an attestation of an artifact using dsse. (id: DSSEAttestationOccurrence) |
envelope | object | https://github.com/secure-systems-lab/dsse (id: Envelope) |
image | object | Describes how this resource derives from the basis in the associated note. (id: ImageOccurrence) |
kind | string | Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests. (NOTE_KIND_UNSPECIFIED, VULNERABILITY, BUILD, IMAGE, PACKAGE, DEPLOYMENT, DISCOVERY, ATTESTATION, UPGRADE, COMPLIANCE, DSSE_ATTESTATION, VULNERABILITY_ASSESSMENT, SBOM_REFERENCE, SECRET, AI_SKILL_ANALYSIS) |
noteName | string | Required. Immutable. The analysis note associated with this occurrence, in the form of projects/[PROVIDER_ID]/notes/[NOTE_ID]. This field can be used as a filter in list requests. |
package | object | Describes the installation of a package on the linked resource. (id: PackageOccurrence) |
remediation | string | A description of actions that can be taken to remedy the note. |
resourceUri | string | Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, https://gcr.io/project/image@sha256:123abc for a Docker image. |
sbomReference | object | Describes a specific SBOM reference occurrences. (id: SBOMReferenceOccurrence) |
secret | object | Describes a secret. (id: SecretOccurrence) |
updateTime | string (google-datetime) | Output only. The time this occurrence was last updated. |
upgrade | object | Describes an available package upgrade on the linked resource. (id: UpgradeOccurrence) |
vulnerability | object | Describes a security vulnerability. (id: VulnerabilityOccurrence) |
| Name | Datatype | Description |
|---|---|---|
name | string | Output only. The name of the occurrence in the form of projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]. |
advisoryPublishTime | string (google-datetime) | The time this advisory was published by the source. |
aiSkillAnalysis | object | Describes an AI skill analysis. (id: AISkillAnalysisOccurrence) |
attestation | object | Describes an attestation of an artifact. (id: AttestationOccurrence) |
build | object | Describes a verifiable build. (id: BuildOccurrence) |
compliance | object | Describes a compliance violation on a linked resource. (id: ComplianceOccurrence) |
createTime | string (google-datetime) | Output only. The time this occurrence was created. |
deployment | object | Describes the deployment of an artifact on a runtime. (id: DeploymentOccurrence) |
discovery | object | Describes when a resource was discovered. (id: DiscoveryOccurrence) |
dsseAttestation | object | Describes an attestation of an artifact using dsse. (id: DSSEAttestationOccurrence) |
envelope | object | https://github.com/secure-systems-lab/dsse (id: Envelope) |
image | object | Describes how this resource derives from the basis in the associated note. (id: ImageOccurrence) |
kind | string | Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests. (NOTE_KIND_UNSPECIFIED, VULNERABILITY, BUILD, IMAGE, PACKAGE, DEPLOYMENT, DISCOVERY, ATTESTATION, UPGRADE, COMPLIANCE, DSSE_ATTESTATION, VULNERABILITY_ASSESSMENT, SBOM_REFERENCE, SECRET, AI_SKILL_ANALYSIS) |
noteName | string | Required. Immutable. The analysis note associated with this occurrence, in the form of projects/[PROVIDER_ID]/notes/[NOTE_ID]. This field can be used as a filter in list requests. |
package | object | Describes the installation of a package on the linked resource. (id: PackageOccurrence) |
remediation | string | A description of actions that can be taken to remedy the note. |
resourceUri | string | Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, https://gcr.io/project/image@sha256:123abc for a Docker image. |
sbomReference | object | Describes a specific SBOM reference occurrences. (id: SBOMReferenceOccurrence) |
secret | object | Describes a secret. (id: SecretOccurrence) |
updateTime | string (google-datetime) | Output only. The time this occurrence was last updated. |
upgrade | object | Describes an available package upgrade on the linked resource. (id: UpgradeOccurrence) |
vulnerability | object | Describes a security vulnerability. (id: VulnerabilityOccurrence) |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
projects_locations_notes_occurrences_list | select | projectsId, locationsId, notesId | filter, pageSize, pageToken | Lists occurrences referencing the specified note. Provider projects can use this method to get all occurrences across consumer projects referencing the specified note. |
projects_locations_occurrences_get | select | projectsId, locationsId, occurrencesId | Gets the specified occurrence. | |
projects_locations_occurrences_list | select | projectsId, locationsId | filter, pageSize, pageToken, returnPartialSuccess | Lists occurrences for the specified project. |
projects_notes_occurrences_list | select | projectsId, notesId | filter, pageSize, pageToken | Lists occurrences referencing the specified note. Provider projects can use this method to get all occurrences across consumer projects referencing the specified note. |
projects_occurrences_get | select | projectsId, occurrencesId | Gets the specified occurrence. | |
projects_occurrences_list | select | projectsId | filter, pageSize, pageToken, returnPartialSuccess | Lists occurrences for the specified project. |
projects_locations_occurrences_batch_create | insert | projectsId, locationsId | Creates new occurrences in batch. | |
projects_locations_occurrences_create | insert | projectsId, locationsId | Creates a new occurrence. | |
projects_occurrences_batch_create | insert | projectsId | Creates new occurrences in batch. | |
projects_occurrences_create | insert | projectsId | Creates a new occurrence. | |
projects_locations_occurrences_patch | update | projectsId, locationsId, occurrencesId | updateMask | Updates the specified occurrence. |
projects_occurrences_patch | update | projectsId, occurrencesId | updateMask | Updates the specified occurrence. |
projects_locations_occurrences_delete | delete | projectsId, locationsId, occurrencesId | Deletes the specified occurrence. For example, use this method to delete an occurrence when the occurrence is no longer applicable for the given resource. | |
projects_occurrences_delete | delete | projectsId, occurrencesId | Deletes the specified occurrence. For example, use this method to delete an occurrence when the occurrence is no longer applicable for the given resource. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
locationsId | string | |
notesId | string | |
occurrencesId | string | |
projectsId | string | |
filter | string | |
pageSize | integer (int32) | |
pageToken | string | |
returnPartialSuccess | boolean | |
updateMask | string (google-fieldmask) |
SELECT examples
- projects_locations_notes_occurrences_list
- projects_locations_occurrences_get
- projects_locations_occurrences_list
- projects_notes_occurrences_list
- projects_occurrences_get
- projects_occurrences_list
Lists occurrences referencing the specified note. Provider projects can use this method to get all occurrences across consumer projects referencing the specified note.
SELECT
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND locationsId = '{{ locationsId }}' -- required
AND notesId = '{{ notesId }}' -- required
AND filter = '{{ filter }}'
AND pageSize = '{{ pageSize }}'
AND pageToken = '{{ pageToken }}'
;
Gets the specified occurrence.
SELECT
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND locationsId = '{{ locationsId }}' -- required
AND occurrencesId = '{{ occurrencesId }}' -- required
;
Lists occurrences for the specified project.
SELECT
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND locationsId = '{{ locationsId }}' -- required
AND filter = '{{ filter }}'
AND pageSize = '{{ pageSize }}'
AND pageToken = '{{ pageToken }}'
AND returnPartialSuccess = '{{ returnPartialSuccess }}'
;
Lists occurrences referencing the specified note. Provider projects can use this method to get all occurrences across consumer projects referencing the specified note.
SELECT
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND notesId = '{{ notesId }}' -- required
AND filter = '{{ filter }}'
AND pageSize = '{{ pageSize }}'
AND pageToken = '{{ pageToken }}'
;
Gets the specified occurrence.
SELECT
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND occurrencesId = '{{ occurrencesId }}' -- required
;
Lists occurrences for the specified project.
SELECT
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' -- required
AND filter = '{{ filter }}'
AND pageSize = '{{ pageSize }}'
AND pageToken = '{{ pageToken }}'
AND returnPartialSuccess = '{{ returnPartialSuccess }}'
;
INSERT examples
- projects_locations_occurrences_batch_create
- projects_locations_occurrences_create
- projects_occurrences_batch_create
- projects_occurrences_create
- Manifest
Creates new occurrences in batch.
INSERT INTO google.containeranalysis.occurrences (
data__occurrences,
projectsId,
locationsId
)
SELECT
'{{ occurrences }}',
'{{ projectsId }}',
'{{ locationsId }}'
RETURNING
occurrences
;
Creates a new occurrence.
INSERT INTO google.containeranalysis.occurrences (
data__advisoryPublishTime,
data__aiSkillAnalysis,
data__attestation,
data__build,
data__compliance,
data__createTime,
data__deployment,
data__discovery,
data__dsseAttestation,
data__envelope,
data__image,
data__kind,
data__name,
data__noteName,
data__package,
data__remediation,
data__resourceUri,
data__sbomReference,
data__secret,
data__updateTime,
data__upgrade,
data__vulnerability,
projectsId,
locationsId
)
SELECT
'{{ advisoryPublishTime }}',
'{{ aiSkillAnalysis }}',
'{{ attestation }}',
'{{ build }}',
'{{ compliance }}',
'{{ createTime }}',
'{{ deployment }}',
'{{ discovery }}',
'{{ dsseAttestation }}',
'{{ envelope }}',
'{{ image }}',
'{{ kind }}',
'{{ name }}',
'{{ noteName }}',
'{{ package }}',
'{{ remediation }}',
'{{ resourceUri }}',
'{{ sbomReference }}',
'{{ secret }}',
'{{ updateTime }}',
'{{ upgrade }}',
'{{ vulnerability }}',
'{{ projectsId }}',
'{{ locationsId }}'
RETURNING
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
;
Creates new occurrences in batch.
INSERT INTO google.containeranalysis.occurrences (
data__occurrences,
projectsId
)
SELECT
'{{ occurrences }}',
'{{ projectsId }}'
RETURNING
occurrences
;
Creates a new occurrence.
INSERT INTO google.containeranalysis.occurrences (
data__advisoryPublishTime,
data__aiSkillAnalysis,
data__attestation,
data__build,
data__compliance,
data__createTime,
data__deployment,
data__discovery,
data__dsseAttestation,
data__envelope,
data__image,
data__kind,
data__name,
data__noteName,
data__package,
data__remediation,
data__resourceUri,
data__sbomReference,
data__secret,
data__updateTime,
data__upgrade,
data__vulnerability,
projectsId
)
SELECT
'{{ advisoryPublishTime }}',
'{{ aiSkillAnalysis }}',
'{{ attestation }}',
'{{ build }}',
'{{ compliance }}',
'{{ createTime }}',
'{{ deployment }}',
'{{ discovery }}',
'{{ dsseAttestation }}',
'{{ envelope }}',
'{{ image }}',
'{{ kind }}',
'{{ name }}',
'{{ noteName }}',
'{{ package }}',
'{{ remediation }}',
'{{ resourceUri }}',
'{{ sbomReference }}',
'{{ secret }}',
'{{ updateTime }}',
'{{ upgrade }}',
'{{ vulnerability }}',
'{{ projectsId }}'
RETURNING
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability
;
# Description fields are for documentation purposes
- name: occurrences
props:
- name: projectsId
value: "{{ projectsId }}"
description: Required parameter for the occurrences resource.
- name: locationsId
value: "{{ locationsId }}"
description: Required parameter for the occurrences resource.
- name: occurrences
description: |
Required. The occurrences to create. Max allowed length is 1000.
value:
- advisoryPublishTime: "{{ advisoryPublishTime }}"
aiSkillAnalysis:
findings:
- category: "{{ category }}"
details: "{{ details }}"
location:
filePath: "{{ filePath }}"
lineNumber: "{{ lineNumber }}"
scanner: "{{ scanner }}"
severity: "{{ severity }}"
maxSeverity: "{{ maxSeverity }}"
perScannerVerdict:
maliciousContentLlmResult:
maxSeverity: "{{ maxSeverity }}"
scanStatus: "{{ scanStatus }}"
maliciousContentStaticResult:
maxSeverity: "{{ maxSeverity }}"
scanStatus: "{{ scanStatus }}"
malwareScan:
scanStatus: "{{ scanStatus }}"
verdict: "{{ verdict }}"
workspacePolicy:
scanStatus: "{{ scanStatus }}"
verdict: "{{ verdict }}"
skillName: "{{ skillName }}"
attestation:
jwts:
- compactJwt: "{{ compactJwt }}"
serializedPayload: "{{ serializedPayload }}"
signatures:
- publicKeyId: "{{ publicKeyId }}"
signature: "{{ signature }}"
build:
inTotoSlsaProvenanceV1:
_type: "{{ _type }}"
predicate:
buildDefinition:
buildType: "{{ buildType }}"
externalParameters: "{{ externalParameters }}"
internalParameters: "{{ internalParameters }}"
resolvedDependencies: "{{ resolvedDependencies }}"
runDetails:
builder: "{{ builder }}"
byproducts: "{{ byproducts }}"
metadata: "{{ metadata }}"
predicateType: "{{ predicateType }}"
subject:
- digest: "{{ digest }}"
name: "{{ name }}"
intotoProvenance:
builderConfig:
id: "{{ id }}"
materials:
- "{{ materials }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
arguments: {{ arguments }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
recipe:
arguments: "{{ arguments }}"
definedInMaterial: "{{ definedInMaterial }}"
entryPoint: "{{ entryPoint }}"
environment: "{{ environment }}"
type: "{{ type }}"
intotoStatement:
_type: "{{ _type }}"
predicateType: "{{ predicateType }}"
provenance:
builderConfig:
id: "{{ id }}"
materials:
- "{{ materials }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
recipe:
arguments: "{{ arguments }}"
definedInMaterial: "{{ definedInMaterial }}"
entryPoint: "{{ entryPoint }}"
environment: "{{ environment }}"
type: "{{ type }}"
slsaProvenance:
builder:
id: "{{ id }}"
materials:
- digest: "{{ digest }}"
uri: "{{ uri }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
recipe:
arguments: "{{ arguments }}"
definedInMaterial: "{{ definedInMaterial }}"
entryPoint: "{{ entryPoint }}"
environment: "{{ environment }}"
type: "{{ type }}"
slsaProvenanceZeroTwo:
buildConfig: "{{ buildConfig }}"
buildType: "{{ buildType }}"
builder:
id: "{{ id }}"
invocation:
configSource: "{{ configSource }}"
environment: "{{ environment }}"
parameters: "{{ parameters }}"
materials:
- digest: "{{ digest }}"
uri: "{{ uri }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
subject:
- digest: "{{ digest }}"
name: "{{ name }}"
provenance:
buildOptions: "{{ buildOptions }}"
builderVersion: "{{ builderVersion }}"
builtArtifacts:
- checksum: "{{ checksum }}"
id: "{{ id }}"
names: "{{ names }}"
commands:
- args: "{{ args }}"
dir: "{{ dir }}"
env: "{{ env }}"
id: "{{ id }}"
name: "{{ name }}"
waitFor: "{{ waitFor }}"
createTime: "{{ createTime }}"
creator: "{{ creator }}"
endTime: "{{ endTime }}"
id: "{{ id }}"
logsUri: "{{ logsUri }}"
projectId: "{{ projectId }}"
sourceProvenance:
additionalContexts:
- cloudRepo:
aliasContext: "{{ aliasContext }}"
repoId: "{{ repoId }}"
revisionId: "{{ revisionId }}"
gerrit:
aliasContext: "{{ aliasContext }}"
gerritProject: "{{ gerritProject }}"
hostUri: "{{ hostUri }}"
revisionId: "{{ revisionId }}"
git:
revisionId: "{{ revisionId }}"
url: "{{ url }}"
labels: "{{ labels }}"
artifactStorageSourceUri: "{{ artifactStorageSourceUri }}"
context:
cloudRepo: "{{ cloudRepo }}"
gerrit: "{{ gerrit }}"
git: "{{ git }}"
labels: "{{ labels }}"
fileHashes: "{{ fileHashes }}"
startTime: "{{ startTime }}"
triggerId: "{{ triggerId }}"
provenanceBytes: "{{ provenanceBytes }}"
compliance:
nonComplianceReason: "{{ nonComplianceReason }}"
nonCompliantFiles:
- displayCommand: "{{ displayCommand }}"
path: "{{ path }}"
reason: "{{ reason }}"
version:
benchmarkDocument: "{{ benchmarkDocument }}"
cpeUri: "{{ cpeUri }}"
version: "{{ version }}"
createTime: "{{ createTime }}"
deployment:
address: "{{ address }}"
config: "{{ config }}"
deployTime: "{{ deployTime }}"
platform: "{{ platform }}"
resourceUri:
- "{{ resourceUri }}"
undeployTime: "{{ undeployTime }}"
userEmail: "{{ userEmail }}"
discovery:
analysisCompleted:
analysisType:
- "{{ analysisType }}"
analysisError:
- code: {{ code }}
details: "{{ details }}"
message: "{{ message }}"
analysisStatus: "{{ analysisStatus }}"
analysisStatusError:
code: {{ code }}
details: "{{ details }}"
message: "{{ message }}"
archiveTime: "{{ archiveTime }}"
continuousAnalysis: "{{ continuousAnalysis }}"
cpe: "{{ cpe }}"
files:
- digest: "{{ digest }}"
name: "{{ name }}"
lastScanTime: "{{ lastScanTime }}"
lastVulnerabilityUpdateTime: "{{ lastVulnerabilityUpdateTime }}"
sbomStatus:
error: "{{ error }}"
sbomState: "{{ sbomState }}"
dsseAttestation:
envelope:
payload: "{{ payload }}"
payloadType: "{{ payloadType }}"
signatures:
- keyid: "{{ keyid }}"
sig: "{{ sig }}"
statement:
_type: "{{ _type }}"
predicateType: "{{ predicateType }}"
provenance:
builderConfig:
id: "{{ id }}"
materials:
- "{{ materials }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
recipe:
arguments: "{{ arguments }}"
definedInMaterial: "{{ definedInMaterial }}"
entryPoint: "{{ entryPoint }}"
environment: "{{ environment }}"
type: "{{ type }}"
slsaProvenance:
builder:
id: "{{ id }}"
materials:
- digest: "{{ digest }}"
uri: "{{ uri }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
recipe:
arguments: "{{ arguments }}"
definedInMaterial: "{{ definedInMaterial }}"
entryPoint: "{{ entryPoint }}"
environment: "{{ environment }}"
type: "{{ type }}"
slsaProvenanceZeroTwo:
buildConfig: "{{ buildConfig }}"
buildType: "{{ buildType }}"
builder:
id: "{{ id }}"
invocation:
configSource: "{{ configSource }}"
environment: "{{ environment }}"
parameters: "{{ parameters }}"
materials:
- digest: "{{ digest }}"
uri: "{{ uri }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness: "{{ completeness }}"
reproducible: {{ reproducible }}
subject:
- digest: "{{ digest }}"
name: "{{ name }}"
envelope:
payload: "{{ payload }}"
payloadType: "{{ payloadType }}"
signatures:
- keyid: "{{ keyid }}"
sig: "{{ sig }}"
image:
baseResourceUrl: "{{ baseResourceUrl }}"
distance: {{ distance }}
fingerprint:
v1Name: "{{ v1Name }}"
v2Blob:
- "{{ v2Blob }}"
v2Name: "{{ v2Name }}"
layerInfo:
- arguments: "{{ arguments }}"
directive: "{{ directive }}"
kind: "{{ kind }}"
name: "{{ name }}"
noteName: "{{ noteName }}"
package:
architecture: "{{ architecture }}"
cpeUri: "{{ cpeUri }}"
license:
comments: "{{ comments }}"
expression: "{{ expression }}"
location:
- cpeUri: "{{ cpeUri }}"
path: "{{ path }}"
version:
epoch: {{ epoch }}
fullName: "{{ fullName }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
name: "{{ name }}"
revision: "{{ revision }}"
name: "{{ name }}"
packageType: "{{ packageType }}"
version:
epoch: {{ epoch }}
fullName: "{{ fullName }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
name: "{{ name }}"
revision: "{{ revision }}"
remediation: "{{ remediation }}"
resourceUri: "{{ resourceUri }}"
sbomReference:
payload:
_type: "{{ _type }}"
predicate:
digest: "{{ digest }}"
location: "{{ location }}"
mimeType: "{{ mimeType }}"
referrerId: "{{ referrerId }}"
predicateType: "{{ predicateType }}"
subject:
- digest: "{{ digest }}"
name: "{{ name }}"
payloadType: "{{ payloadType }}"
signatures:
- keyid: "{{ keyid }}"
sig: "{{ sig }}"
secret:
kind: "{{ kind }}"
locations:
- fileLocation:
filePath: "{{ filePath }}"
layerDetails:
baseImages: "{{ baseImages }}"
chainId: "{{ chainId }}"
command: "{{ command }}"
diffId: "{{ diffId }}"
index: {{ index }}
lineNumber: {{ lineNumber }}
statuses:
- message: "{{ message }}"
status: "{{ status }}"
updateTime: "{{ updateTime }}"
updateTime: "{{ updateTime }}"
upgrade:
distribution:
classification: "{{ classification }}"
cpeUri: "{{ cpeUri }}"
cve:
- "{{ cve }}"
severity: "{{ severity }}"
package: "{{ package }}"
parsedVersion:
epoch: {{ epoch }}
fullName: "{{ fullName }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
name: "{{ name }}"
revision: "{{ revision }}"
windowsUpdate:
categories:
- categoryId: "{{ categoryId }}"
name: "{{ name }}"
description: "{{ description }}"
identity:
revision: {{ revision }}
updateId: "{{ updateId }}"
kbArticleIds:
- "{{ kbArticleIds }}"
lastPublishedTimestamp: "{{ lastPublishedTimestamp }}"
supportUrl: "{{ supportUrl }}"
title: "{{ title }}"
vulnerability:
cvssScore: {{ cvssScore }}
cvssV2:
attackComplexity: "{{ attackComplexity }}"
attackRequirements: "{{ attackRequirements }}"
attackVector: "{{ attackVector }}"
authentication: "{{ authentication }}"
availabilityImpact: "{{ availabilityImpact }}"
baseScore: {{ baseScore }}
confidentialityImpact: "{{ confidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
exploitabilityScore: {{ exploitabilityScore }}
impactScore: {{ impactScore }}
integrityImpact: "{{ integrityImpact }}"
privilegesRequired: "{{ privilegesRequired }}"
scope: "{{ scope }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
cvssV4:
attackComplexity: "{{ attackComplexity }}"
attackRequirements: "{{ attackRequirements }}"
attackVector: "{{ attackVector }}"
authentication: "{{ authentication }}"
availabilityImpact: "{{ availabilityImpact }}"
baseScore: {{ baseScore }}
confidentialityImpact: "{{ confidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
exploitabilityScore: {{ exploitabilityScore }}
impactScore: {{ impactScore }}
integrityImpact: "{{ integrityImpact }}"
privilegesRequired: "{{ privilegesRequired }}"
scope: "{{ scope }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
cvssVersion: "{{ cvssVersion }}"
cvssv3:
attackComplexity: "{{ attackComplexity }}"
attackRequirements: "{{ attackRequirements }}"
attackVector: "{{ attackVector }}"
authentication: "{{ authentication }}"
availabilityImpact: "{{ availabilityImpact }}"
baseScore: {{ baseScore }}
confidentialityImpact: "{{ confidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
exploitabilityScore: {{ exploitabilityScore }}
impactScore: {{ impactScore }}
integrityImpact: "{{ integrityImpact }}"
privilegesRequired: "{{ privilegesRequired }}"
scope: "{{ scope }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
effectiveSeverity: "{{ effectiveSeverity }}"
extraDetails: "{{ extraDetails }}"
fixAvailable: {{ fixAvailable }}
longDescription: "{{ longDescription }}"
packageIssue:
- affectedCpeUri: "{{ affectedCpeUri }}"
affectedPackage: "{{ affectedPackage }}"
affectedVersion:
epoch: {{ epoch }}
fullName: "{{ fullName }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
name: "{{ name }}"
revision: "{{ revision }}"
effectiveSeverity: "{{ effectiveSeverity }}"
fileLocation: "{{ fileLocation }}"
fixAvailable: {{ fixAvailable }}
fixedCpeUri: "{{ fixedCpeUri }}"
fixedPackage: "{{ fixedPackage }}"
fixedVersion:
epoch: {{ epoch }}
fullName: "{{ fullName }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
name: "{{ name }}"
revision: "{{ revision }}"
packageType: "{{ packageType }}"
relatedUrls:
- label: "{{ label }}"
url: "{{ url }}"
risk:
cisaKev:
knownRansomwareCampaignUse: "{{ knownRansomwareCampaignUse }}"
epss:
percentile: {{ percentile }}
score: {{ score }}
severity: "{{ severity }}"
shortDescription: "{{ shortDescription }}"
type: "{{ type }}"
vexAssessment:
cve: "{{ cve }}"
impacts:
- "{{ impacts }}"
justification:
details: "{{ details }}"
justificationType: "{{ justificationType }}"
noteName: "{{ noteName }}"
relatedUris:
- label: "{{ label }}"
url: "{{ url }}"
remediations:
- details: "{{ details }}"
remediationType: "{{ remediationType }}"
remediationUri:
label: "{{ label }}"
url: "{{ url }}"
state: "{{ state }}"
vulnerabilityId: "{{ vulnerabilityId }}"
- name: advisoryPublishTime
value: "{{ advisoryPublishTime }}"
description: |
The time this advisory was published by the source.
- name: aiSkillAnalysis
description: |
Describes an AI skill analysis.
value:
findings:
- category: "{{ category }}"
details: "{{ details }}"
location:
filePath: "{{ filePath }}"
lineNumber: "{{ lineNumber }}"
scanner: "{{ scanner }}"
severity: "{{ severity }}"
maxSeverity: "{{ maxSeverity }}"
perScannerVerdict:
maliciousContentLlmResult:
maxSeverity: "{{ maxSeverity }}"
scanStatus: "{{ scanStatus }}"
maliciousContentStaticResult:
maxSeverity: "{{ maxSeverity }}"
scanStatus: "{{ scanStatus }}"
malwareScan:
scanStatus: "{{ scanStatus }}"
verdict: "{{ verdict }}"
workspacePolicy:
scanStatus: "{{ scanStatus }}"
verdict: "{{ verdict }}"
skillName: "{{ skillName }}"
- name: attestation
description: |
Describes an attestation of an artifact.
value:
jwts:
- compactJwt: "{{ compactJwt }}"
serializedPayload: "{{ serializedPayload }}"
signatures:
- publicKeyId: "{{ publicKeyId }}"
signature: "{{ signature }}"
- name: build
description: |
Describes a verifiable build.
value:
inTotoSlsaProvenanceV1:
_type: "{{ _type }}"
predicate:
buildDefinition:
buildType: "{{ buildType }}"
externalParameters: "{{ externalParameters }}"
internalParameters: "{{ internalParameters }}"
resolvedDependencies:
- annotations: "{{ annotations }}"
content: "{{ content }}"
digest: "{{ digest }}"
downloadLocation: "{{ downloadLocation }}"
mediaType: "{{ mediaType }}"
name: "{{ name }}"
uri: "{{ uri }}"
runDetails:
builder:
builderDependencies: "{{ builderDependencies }}"
id: "{{ id }}"
version: "{{ version }}"
byproducts:
- annotations: "{{ annotations }}"
content: "{{ content }}"
digest: "{{ digest }}"
downloadLocation: "{{ downloadLocation }}"
mediaType: "{{ mediaType }}"
name: "{{ name }}"
uri: "{{ uri }}"
metadata:
finishedOn: "{{ finishedOn }}"
invocationId: "{{ invocationId }}"
startedOn: "{{ startedOn }}"
predicateType: "{{ predicateType }}"
subject:
- digest: "{{ digest }}"
name: "{{ name }}"
intotoProvenance:
builderConfig:
id: "{{ id }}"
materials:
- "{{ materials }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
arguments: {{ arguments }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
recipe:
arguments: "{{ arguments }}"
definedInMaterial: "{{ definedInMaterial }}"
entryPoint: "{{ entryPoint }}"
environment: "{{ environment }}"
type: "{{ type }}"
intotoStatement:
_type: "{{ _type }}"
predicateType: "{{ predicateType }}"
provenance:
builderConfig:
id: "{{ id }}"
materials:
- "{{ materials }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
arguments: {{ arguments }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
recipe:
arguments: "{{ arguments }}"
definedInMaterial: "{{ definedInMaterial }}"
entryPoint: "{{ entryPoint }}"
environment: "{{ environment }}"
type: "{{ type }}"
slsaProvenance:
builder:
id: "{{ id }}"
materials:
- digest: "{{ digest }}"
uri: "{{ uri }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
arguments: {{ arguments }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
recipe:
arguments: "{{ arguments }}"
definedInMaterial: "{{ definedInMaterial }}"
entryPoint: "{{ entryPoint }}"
environment: "{{ environment }}"
type: "{{ type }}"
slsaProvenanceZeroTwo:
buildConfig: "{{ buildConfig }}"
buildType: "{{ buildType }}"
builder:
id: "{{ id }}"
invocation:
configSource:
digest: "{{ digest }}"
entryPoint: "{{ entryPoint }}"
uri: "{{ uri }}"
environment: "{{ environment }}"
parameters: "{{ parameters }}"
materials:
- digest: "{{ digest }}"
uri: "{{ uri }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
environment: {{ environment }}
materials: {{ materials }}
parameters: {{ parameters }}
reproducible: {{ reproducible }}
subject:
- digest: "{{ digest }}"
name: "{{ name }}"
provenance:
buildOptions: "{{ buildOptions }}"
builderVersion: "{{ builderVersion }}"
builtArtifacts:
- checksum: "{{ checksum }}"
id: "{{ id }}"
names: "{{ names }}"
commands:
- args: "{{ args }}"
dir: "{{ dir }}"
env: "{{ env }}"
id: "{{ id }}"
name: "{{ name }}"
waitFor: "{{ waitFor }}"
createTime: "{{ createTime }}"
creator: "{{ creator }}"
endTime: "{{ endTime }}"
id: "{{ id }}"
logsUri: "{{ logsUri }}"
projectId: "{{ projectId }}"
sourceProvenance:
additionalContexts:
- cloudRepo:
aliasContext: "{{ aliasContext }}"
repoId: "{{ repoId }}"
revisionId: "{{ revisionId }}"
gerrit:
aliasContext: "{{ aliasContext }}"
gerritProject: "{{ gerritProject }}"
hostUri: "{{ hostUri }}"
revisionId: "{{ revisionId }}"
git:
revisionId: "{{ revisionId }}"
url: "{{ url }}"
labels: "{{ labels }}"
artifactStorageSourceUri: "{{ artifactStorageSourceUri }}"
context:
cloudRepo:
aliasContext: "{{ aliasContext }}"
repoId: "{{ repoId }}"
revisionId: "{{ revisionId }}"
gerrit:
aliasContext: "{{ aliasContext }}"
gerritProject: "{{ gerritProject }}"
hostUri: "{{ hostUri }}"
revisionId: "{{ revisionId }}"
git:
revisionId: "{{ revisionId }}"
url: "{{ url }}"
labels: "{{ labels }}"
fileHashes: "{{ fileHashes }}"
startTime: "{{ startTime }}"
triggerId: "{{ triggerId }}"
provenanceBytes: "{{ provenanceBytes }}"
- name: compliance
description: |
Describes a compliance violation on a linked resource.
value:
nonComplianceReason: "{{ nonComplianceReason }}"
nonCompliantFiles:
- displayCommand: "{{ displayCommand }}"
path: "{{ path }}"
reason: "{{ reason }}"
version:
benchmarkDocument: "{{ benchmarkDocument }}"
cpeUri: "{{ cpeUri }}"
version: "{{ version }}"
- name: createTime
value: "{{ createTime }}"
description: |
Output only. The time this occurrence was created.
- name: deployment
description: |
Describes the deployment of an artifact on a runtime.
value:
address: "{{ address }}"
config: "{{ config }}"
deployTime: "{{ deployTime }}"
platform: "{{ platform }}"
resourceUri:
- "{{ resourceUri }}"
undeployTime: "{{ undeployTime }}"
userEmail: "{{ userEmail }}"
- name: discovery
description: |
Describes when a resource was discovered.
value:
analysisCompleted:
analysisType:
- "{{ analysisType }}"
analysisError:
- code: {{ code }}
details: "{{ details }}"
message: "{{ message }}"
analysisStatus: "{{ analysisStatus }}"
analysisStatusError:
code: {{ code }}
details: "{{ details }}"
message: "{{ message }}"
archiveTime: "{{ archiveTime }}"
continuousAnalysis: "{{ continuousAnalysis }}"
cpe: "{{ cpe }}"
files:
- digest: "{{ digest }}"
name: "{{ name }}"
lastScanTime: "{{ lastScanTime }}"
lastVulnerabilityUpdateTime: "{{ lastVulnerabilityUpdateTime }}"
sbomStatus:
error: "{{ error }}"
sbomState: "{{ sbomState }}"
- name: dsseAttestation
description: |
Describes an attestation of an artifact using dsse.
value:
envelope:
payload: "{{ payload }}"
payloadType: "{{ payloadType }}"
signatures:
- keyid: "{{ keyid }}"
sig: "{{ sig }}"
statement:
_type: "{{ _type }}"
predicateType: "{{ predicateType }}"
provenance:
builderConfig:
id: "{{ id }}"
materials:
- "{{ materials }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
arguments: {{ arguments }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
recipe:
arguments: "{{ arguments }}"
definedInMaterial: "{{ definedInMaterial }}"
entryPoint: "{{ entryPoint }}"
environment: "{{ environment }}"
type: "{{ type }}"
slsaProvenance:
builder:
id: "{{ id }}"
materials:
- digest: "{{ digest }}"
uri: "{{ uri }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
arguments: {{ arguments }}
environment: {{ environment }}
materials: {{ materials }}
reproducible: {{ reproducible }}
recipe:
arguments: "{{ arguments }}"
definedInMaterial: "{{ definedInMaterial }}"
entryPoint: "{{ entryPoint }}"
environment: "{{ environment }}"
type: "{{ type }}"
slsaProvenanceZeroTwo:
buildConfig: "{{ buildConfig }}"
buildType: "{{ buildType }}"
builder:
id: "{{ id }}"
invocation:
configSource:
digest: "{{ digest }}"
entryPoint: "{{ entryPoint }}"
uri: "{{ uri }}"
environment: "{{ environment }}"
parameters: "{{ parameters }}"
materials:
- digest: "{{ digest }}"
uri: "{{ uri }}"
metadata:
buildFinishedOn: "{{ buildFinishedOn }}"
buildInvocationId: "{{ buildInvocationId }}"
buildStartedOn: "{{ buildStartedOn }}"
completeness:
environment: {{ environment }}
materials: {{ materials }}
parameters: {{ parameters }}
reproducible: {{ reproducible }}
subject:
- digest: "{{ digest }}"
name: "{{ name }}"
- name: envelope
description: |
https://github.com/secure-systems-lab/dsse
value:
payload: "{{ payload }}"
payloadType: "{{ payloadType }}"
signatures:
- keyid: "{{ keyid }}"
sig: "{{ sig }}"
- name: image
description: |
Describes how this resource derives from the basis in the associated note.
value:
baseResourceUrl: "{{ baseResourceUrl }}"
distance: {{ distance }}
fingerprint:
v1Name: "{{ v1Name }}"
v2Blob:
- "{{ v2Blob }}"
v2Name: "{{ v2Name }}"
layerInfo:
- arguments: "{{ arguments }}"
directive: "{{ directive }}"
- name: kind
value: "{{ kind }}"
description: |
Output only. This explicitly denotes which of the occurrence details are specified. This field can be used as a filter in list requests.
valid_values: ['NOTE_KIND_UNSPECIFIED', 'VULNERABILITY', 'BUILD', 'IMAGE', 'PACKAGE', 'DEPLOYMENT', 'DISCOVERY', 'ATTESTATION', 'UPGRADE', 'COMPLIANCE', 'DSSE_ATTESTATION', 'VULNERABILITY_ASSESSMENT', 'SBOM_REFERENCE', 'SECRET', 'AI_SKILL_ANALYSIS']
- name: name
value: "{{ name }}"
description: |
Output only. The name of the occurrence in the form of `projects/[PROJECT_ID]/occurrences/[OCCURRENCE_ID]`.
- name: noteName
value: "{{ noteName }}"
description: |
Required. Immutable. The analysis note associated with this occurrence, in the form of `projects/[PROVIDER_ID]/notes/[NOTE_ID]`. This field can be used as a filter in list requests.
- name: package
description: |
Describes the installation of a package on the linked resource.
value:
architecture: "{{ architecture }}"
cpeUri: "{{ cpeUri }}"
license:
comments: "{{ comments }}"
expression: "{{ expression }}"
location:
- cpeUri: "{{ cpeUri }}"
path: "{{ path }}"
version:
epoch: {{ epoch }}
fullName: "{{ fullName }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
name: "{{ name }}"
revision: "{{ revision }}"
name: "{{ name }}"
packageType: "{{ packageType }}"
version:
epoch: {{ epoch }}
fullName: "{{ fullName }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
name: "{{ name }}"
revision: "{{ revision }}"
- name: remediation
value: "{{ remediation }}"
description: |
A description of actions that can be taken to remedy the note.
- name: resourceUri
value: "{{ resourceUri }}"
description: |
Required. Immutable. A URI that represents the resource for which the occurrence applies. For example, `https://gcr.io/project/image@sha256:123abc` for a Docker image.
- name: sbomReference
description: |
Describes a specific SBOM reference occurrences.
value:
payload:
_type: "{{ _type }}"
predicate:
digest: "{{ digest }}"
location: "{{ location }}"
mimeType: "{{ mimeType }}"
referrerId: "{{ referrerId }}"
predicateType: "{{ predicateType }}"
subject:
- digest: "{{ digest }}"
name: "{{ name }}"
payloadType: "{{ payloadType }}"
signatures:
- keyid: "{{ keyid }}"
sig: "{{ sig }}"
- name: secret
description: |
Describes a secret.
value:
kind: "{{ kind }}"
locations:
- fileLocation:
filePath: "{{ filePath }}"
layerDetails:
baseImages:
- layerCount: {{ layerCount }}
name: "{{ name }}"
registry: "{{ registry }}"
repository: "{{ repository }}"
chainId: "{{ chainId }}"
command: "{{ command }}"
diffId: "{{ diffId }}"
index: {{ index }}
lineNumber: {{ lineNumber }}
statuses:
- message: "{{ message }}"
status: "{{ status }}"
updateTime: "{{ updateTime }}"
- name: updateTime
value: "{{ updateTime }}"
description: |
Output only. The time this occurrence was last updated.
- name: upgrade
description: |
Describes an available package upgrade on the linked resource.
value:
distribution:
classification: "{{ classification }}"
cpeUri: "{{ cpeUri }}"
cve:
- "{{ cve }}"
severity: "{{ severity }}"
package: "{{ package }}"
parsedVersion:
epoch: {{ epoch }}
fullName: "{{ fullName }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
name: "{{ name }}"
revision: "{{ revision }}"
windowsUpdate:
categories:
- categoryId: "{{ categoryId }}"
name: "{{ name }}"
description: "{{ description }}"
identity:
revision: {{ revision }}
updateId: "{{ updateId }}"
kbArticleIds:
- "{{ kbArticleIds }}"
lastPublishedTimestamp: "{{ lastPublishedTimestamp }}"
supportUrl: "{{ supportUrl }}"
title: "{{ title }}"
- name: vulnerability
description: |
Describes a security vulnerability.
value:
cvssScore: {{ cvssScore }}
cvssV2:
attackComplexity: "{{ attackComplexity }}"
attackRequirements: "{{ attackRequirements }}"
attackVector: "{{ attackVector }}"
authentication: "{{ authentication }}"
availabilityImpact: "{{ availabilityImpact }}"
baseScore: {{ baseScore }}
confidentialityImpact: "{{ confidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
exploitabilityScore: {{ exploitabilityScore }}
impactScore: {{ impactScore }}
integrityImpact: "{{ integrityImpact }}"
privilegesRequired: "{{ privilegesRequired }}"
scope: "{{ scope }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
cvssV4:
attackComplexity: "{{ attackComplexity }}"
attackRequirements: "{{ attackRequirements }}"
attackVector: "{{ attackVector }}"
authentication: "{{ authentication }}"
availabilityImpact: "{{ availabilityImpact }}"
baseScore: {{ baseScore }}
confidentialityImpact: "{{ confidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
exploitabilityScore: {{ exploitabilityScore }}
impactScore: {{ impactScore }}
integrityImpact: "{{ integrityImpact }}"
privilegesRequired: "{{ privilegesRequired }}"
scope: "{{ scope }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
cvssVersion: "{{ cvssVersion }}"
cvssv3:
attackComplexity: "{{ attackComplexity }}"
attackRequirements: "{{ attackRequirements }}"
attackVector: "{{ attackVector }}"
authentication: "{{ authentication }}"
availabilityImpact: "{{ availabilityImpact }}"
baseScore: {{ baseScore }}
confidentialityImpact: "{{ confidentialityImpact }}"
exploitMaturity: "{{ exploitMaturity }}"
exploitabilityScore: {{ exploitabilityScore }}
impactScore: {{ impactScore }}
integrityImpact: "{{ integrityImpact }}"
privilegesRequired: "{{ privilegesRequired }}"
scope: "{{ scope }}"
subsequentSystemAvailabilityImpact: "{{ subsequentSystemAvailabilityImpact }}"
subsequentSystemConfidentialityImpact: "{{ subsequentSystemConfidentialityImpact }}"
subsequentSystemIntegrityImpact: "{{ subsequentSystemIntegrityImpact }}"
userInteraction: "{{ userInteraction }}"
vulnerableSystemAvailabilityImpact: "{{ vulnerableSystemAvailabilityImpact }}"
vulnerableSystemConfidentialityImpact: "{{ vulnerableSystemConfidentialityImpact }}"
vulnerableSystemIntegrityImpact: "{{ vulnerableSystemIntegrityImpact }}"
effectiveSeverity: "{{ effectiveSeverity }}"
extraDetails: "{{ extraDetails }}"
fixAvailable: {{ fixAvailable }}
longDescription: "{{ longDescription }}"
packageIssue:
- affectedCpeUri: "{{ affectedCpeUri }}"
affectedPackage: "{{ affectedPackage }}"
affectedVersion:
epoch: {{ epoch }}
fullName: "{{ fullName }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
name: "{{ name }}"
revision: "{{ revision }}"
effectiveSeverity: "{{ effectiveSeverity }}"
fileLocation: "{{ fileLocation }}"
fixAvailable: {{ fixAvailable }}
fixedCpeUri: "{{ fixedCpeUri }}"
fixedPackage: "{{ fixedPackage }}"
fixedVersion:
epoch: {{ epoch }}
fullName: "{{ fullName }}"
inclusive: {{ inclusive }}
kind: "{{ kind }}"
name: "{{ name }}"
revision: "{{ revision }}"
packageType: "{{ packageType }}"
relatedUrls:
- label: "{{ label }}"
url: "{{ url }}"
risk:
cisaKev:
knownRansomwareCampaignUse: "{{ knownRansomwareCampaignUse }}"
epss:
percentile: {{ percentile }}
score: {{ score }}
severity: "{{ severity }}"
shortDescription: "{{ shortDescription }}"
type: "{{ type }}"
vexAssessment:
cve: "{{ cve }}"
impacts:
- "{{ impacts }}"
justification:
details: "{{ details }}"
justificationType: "{{ justificationType }}"
noteName: "{{ noteName }}"
relatedUris:
- label: "{{ label }}"
url: "{{ url }}"
remediations:
- details: "{{ details }}"
remediationType: "{{ remediationType }}"
remediationUri:
label: "{{ label }}"
url: "{{ url }}"
state: "{{ state }}"
vulnerabilityId: "{{ vulnerabilityId }}"
UPDATE examples
- projects_locations_occurrences_patch
- projects_occurrences_patch
Updates the specified occurrence.
UPDATE google.containeranalysis.occurrences
SET
data__advisoryPublishTime = '{{ advisoryPublishTime }}',
data__aiSkillAnalysis = '{{ aiSkillAnalysis }}',
data__attestation = '{{ attestation }}',
data__build = '{{ build }}',
data__compliance = '{{ compliance }}',
data__createTime = '{{ createTime }}',
data__deployment = '{{ deployment }}',
data__discovery = '{{ discovery }}',
data__dsseAttestation = '{{ dsseAttestation }}',
data__envelope = '{{ envelope }}',
data__image = '{{ image }}',
data__kind = '{{ kind }}',
data__name = '{{ name }}',
data__noteName = '{{ noteName }}',
data__package = '{{ package }}',
data__remediation = '{{ remediation }}',
data__resourceUri = '{{ resourceUri }}',
data__sbomReference = '{{ sbomReference }}',
data__secret = '{{ secret }}',
data__updateTime = '{{ updateTime }}',
data__upgrade = '{{ upgrade }}',
data__vulnerability = '{{ vulnerability }}'
WHERE
projectsId = '{{ projectsId }}' --required
AND locationsId = '{{ locationsId }}' --required
AND occurrencesId = '{{ occurrencesId }}' --required
AND updateMask = '{{ updateMask}}'
RETURNING
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability;
Updates the specified occurrence.
UPDATE google.containeranalysis.occurrences
SET
data__advisoryPublishTime = '{{ advisoryPublishTime }}',
data__aiSkillAnalysis = '{{ aiSkillAnalysis }}',
data__attestation = '{{ attestation }}',
data__build = '{{ build }}',
data__compliance = '{{ compliance }}',
data__createTime = '{{ createTime }}',
data__deployment = '{{ deployment }}',
data__discovery = '{{ discovery }}',
data__dsseAttestation = '{{ dsseAttestation }}',
data__envelope = '{{ envelope }}',
data__image = '{{ image }}',
data__kind = '{{ kind }}',
data__name = '{{ name }}',
data__noteName = '{{ noteName }}',
data__package = '{{ package }}',
data__remediation = '{{ remediation }}',
data__resourceUri = '{{ resourceUri }}',
data__sbomReference = '{{ sbomReference }}',
data__secret = '{{ secret }}',
data__updateTime = '{{ updateTime }}',
data__upgrade = '{{ upgrade }}',
data__vulnerability = '{{ vulnerability }}'
WHERE
projectsId = '{{ projectsId }}' --required
AND occurrencesId = '{{ occurrencesId }}' --required
AND updateMask = '{{ updateMask}}'
RETURNING
name,
advisoryPublishTime,
aiSkillAnalysis,
attestation,
build,
compliance,
createTime,
deployment,
discovery,
dsseAttestation,
envelope,
image,
kind,
noteName,
package,
remediation,
resourceUri,
sbomReference,
secret,
updateTime,
upgrade,
vulnerability;
DELETE examples
- projects_locations_occurrences_delete
- projects_occurrences_delete
Deletes the specified occurrence. For example, use this method to delete an occurrence when the occurrence is no longer applicable for the given resource.
DELETE FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' --required
AND locationsId = '{{ locationsId }}' --required
AND occurrencesId = '{{ occurrencesId }}' --required
;
Deletes the specified occurrence. For example, use this method to delete an occurrence when the occurrence is no longer applicable for the given resource.
DELETE FROM google.containeranalysis.occurrences
WHERE projectsId = '{{ projectsId }}' --required
AND occurrencesId = '{{ occurrencesId }}' --required
;