Skip to content

GCP.ContainerAnalysis reference

Source: src/GCP/ContainerAnalysis/GetNote.ts

Runtime binding for Container Analysis notes.get.

Bind this operation to a Note in a Function/Action init phase. Provide GetNoteHttp.

const getNote = yield* GCP.ContainerAnalysis.GetNote(note);
const live = yield* getNote();

Source: src/GCP/ContainerAnalysis/GetNoteHttp.ts Kind: Layer · Provides: GCP.ContainerAnalysis.GetNote

HTTP implementation of GetNote.

Source: src/GCP/ContainerAnalysis/GetOccurrence.ts

Runtime binding for Container Analysis occurrences.get.

Bind this operation to an Occurrence in a Function/Action init phase. Provide GetOccurrenceHttp.

const getOccurrence = yield* GCP.ContainerAnalysis.GetOccurrence(
occurrence,
);
const live = yield* getOccurrence();

Source: src/GCP/ContainerAnalysis/GetOccurrenceHttp.ts Kind: Layer · Provides: GCP.ContainerAnalysis.GetOccurrence

HTTP implementation of GetOccurrence.

Source: src/GCP/ContainerAnalysis/LocationsNote.ts

A location-scoped Container Analysis (Grafeas) note. Same shape as Note, stored at projects/{project}/locations/{location}/notes/{note}.

Location and note id are identity. Alchemy stamps ownership into longDescription for list / nuke.

const note = yield* GCP.ContainerAnalysis.LocationsNote("Authority", {
location: "us-central1",
shortDescription: "qa attestor",
attestation: { hint: { humanReadableName: "QA" } },
});

Source: src/GCP/ContainerAnalysis/LocationsOccurrence.ts

A location-scoped Container Analysis (Grafeas) occurrence. Same shape as Occurrence, stored at projects/{project}/locations/{location}/occurrences/{occurrence}.

Location, noteName, and resourceUri are identity. Alchemy stamps ownership into remediation for list / nuke.

LocationsOccurrence: Creating a Locations Occurrence

Section titled “LocationsOccurrence: Creating a Locations Occurrence”
const note = yield* GCP.ContainerAnalysis.LocationsNote("Authority", {
location: "us-central1",
attestation: { hint: { humanReadableName: "QA" } },
});
const occurrence = yield* GCP.ContainerAnalysis.LocationsOccurrence(
"Signed",
{
location: "us-central1",
noteName: note.name,
resourceUri: "https://example.com/image@sha256:abc",
attestation: {
serializedPayload: btoa("payload"),
signatures: [
{
publicKeyId: "https://example.com/keys/qa",
signature: btoa("sig"),
},
],
},
},
);

Source: src/GCP/ContainerAnalysis/Note.ts

A project-scoped Container Analysis (Grafeas) note. Notes describe a type of analysis; occurrences attach a note to a resource such as a container image.

Notes have no labels field, so Alchemy stamps ownership into longDescription for list / nuke. noteId is identity — changing it replaces the note. Descriptions, related URLs, and kind payloads update in place. Switching the analysis kind replaces the note.

Attestation authority

const note = yield* GCP.ContainerAnalysis.Note("Authority", {
shortDescription: "qa attestor",
attestation: { hint: { humanReadableName: "QA" } },
});

Explicit id and related URL

const note = yield* GCP.ContainerAnalysis.Note("Authority", {
noteId: "qa-attestor",
shortDescription: "qa attestor",
longDescription: "signs production images",
relatedUrl: [{ url: "https://example.com/policy", label: "policy" }],
attestation: { hint: { humanReadableName: "QA" } },
});

Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.

const note = yield* GCP.ContainerAnalysis.Note("Authority", {
shortDescription: "qa and staging attestor",
attestation: { hint: { humanReadableName: "QA" } },
});

Source: src/GCP/ContainerAnalysis/Occurrence.ts

A project-scoped Container Analysis (Grafeas) occurrence. Occurrences attach a note to a concrete resource URI such as a container image digest.

The occurrence id is assigned by the API. noteName and resourceUri are identity — changing either replaces the occurrence. Occurrences have no labels field, so Alchemy stamps ownership into remediation for list / nuke.

const note = yield* GCP.ContainerAnalysis.Note("Authority", {
attestation: { hint: { humanReadableName: "QA" } },
});
const occurrence = yield* GCP.ContainerAnalysis.Occurrence("Signed", {
noteName: note.name,
resourceUri: "https://example.com/image@sha256:abc",
attestation: {
serializedPayload: btoa("payload"),
signatures: [
{ publicKeyId: "https://example.com/keys/qa", signature: btoa("sig") },
],
},
});

Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.

const occurrence = yield* GCP.ContainerAnalysis.Occurrence("Signed", {
noteName: note.name,
resourceUri: "https://example.com/image@sha256:abc",
remediation: "rebuild from a patched base",
attestation: { hint: { humanReadableName: "QA" } },
});