azure-acr-repository-artifact-content

Container images and OCI artifacts can contain embedded secrets in layers, histories, or configuration.

azurecritical service: azure:acr emits CanReadData

Where it sits

locationOCI registry manifest, layer, configuration, and artifact blobs
location kindcode_artifact
data kindscredential password api_key access_key secret_key oauth_token connection_string private_key source_code_secret
emits edgeCanReadData
serviceContainer Registry (azure:acr)

Collection recipe

access modedata_plane
operationOCI Distribution pull manifest/blob
response path$value
encodingbinary
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.ContainerRegistry/registries/repositories/content/read

References

move · open · esc close