gcp-dataflow-job-environment-options

Pipeline options and worker metadata are free-form structures that may persist connector credentials or sensitive arguments.

gcpcritical service: gcp:dataflow emits ContainsCredential

Where it sits

locationdataflow.projects.locations.jobs.get.environment.{sdkPipelineOptions,workerPools[].metadata.<value>,userAgent,version}
location kindconfig_field
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data
emits edgeContainsCredential
serviceDataflow (gcp:dataflow)

Collection recipe

access moderead_api
operationdataflow.projects.locations.jobs.get
response pathenvironment.{sdkPipelineOptions,workerPools[].metadata.<value>,userAgent,version}
encodingjson
params{"name": "\u003cresource-name\u003e"}

Required permissions

dataflow.jobs.get

References

move · open · esc close