gcp-clouddeploy-release-build-artifacts

Release artifact references lead to manifests and configuration that may contain embedded credentials.

gcpcritical service: gcp:clouddeploy emits ContainsCredential

Where it sits

locationclouddeploy.projects.locations.deliveryPipelines.releases.get.buildArtifacts[].{image,skaffoldConfigUri,manifestPath}
location kindcode_artifact
data kindssource_code_secret credential password api_key private_key
emits edgeContainsCredential
serviceCloud Deploy (gcp:clouddeploy)

Collection recipe

access modeindirect_destination
operationclouddeploy.projects.locations.deliveryPipelines.releases.get
response pathbuildArtifacts[].{image,skaffoldConfigUri,manifestPath}
encodingbinary
params{"name": "\u003cresource-name\u003e"}

Required permissions

clouddeploy.releases.get
storage.objects.get

References

move · open · esc close