gcp-gcf-source-archive

A function's source archive can contain hard-coded credentials and sensitive configuration files.

gcpcritical service: gcp:gcf emits ContainsCredential

Where it sits

locationcloudfunctions.projects.locations.functions.get.buildConfig.source.storageSource -> Cloud Storage object bytes
location kindcode_artifact
data kindssource_code_secret credential password api_key private_key
emits edgeContainsCredential
serviceCloud Functions (gcp:gcf)

Collection recipe

access modeindirect_destination
operationcloudfunctions.projects.locations.functions.get
response pathbuildConfig.source.storageSource -> Cloud Storage object bytes
encodingbinary
params{"name": "\u003cresource-name\u003e"}

Required permissions

cloudfunctions.functions.get
storage.objects.get

References

move · open · esc close