GCP.ContainerAnalysis reference
GetNote
Section titled “GetNote”Source:
src/GCP/ContainerAnalysis/GetNote.ts
Runtime binding for Container Analysis notes.get.
Bind this operation to a Note in a Function/Action init
phase. Provide GetNoteHttp.
GetNote: Reading a Note
Section titled “GetNote: Reading a Note”const getNote = yield* GCP.ContainerAnalysis.GetNote(note);const live = yield* getNote();GetNoteHttp
Section titled “GetNoteHttp”Source:
src/GCP/ContainerAnalysis/GetNoteHttp.tsKind: Layer · Provides:GCP.ContainerAnalysis.GetNote
HTTP implementation of GetNote.
GetOccurrence
Section titled “GetOccurrence”Source:
src/GCP/ContainerAnalysis/GetOccurrence.ts
Runtime binding for Container Analysis occurrences.get.
Bind this operation to an Occurrence in a Function/Action
init phase. Provide GetOccurrenceHttp.
GetOccurrence: Reading an Occurrence
Section titled “GetOccurrence: Reading an Occurrence”const getOccurrence = yield* GCP.ContainerAnalysis.GetOccurrence( occurrence,);const live = yield* getOccurrence();GetOccurrenceHttp
Section titled “GetOccurrenceHttp”Source:
src/GCP/ContainerAnalysis/GetOccurrenceHttp.tsKind: Layer · Provides:GCP.ContainerAnalysis.GetOccurrence
HTTP implementation of GetOccurrence.
LocationsNote
Section titled “LocationsNote”Source:
src/GCP/ContainerAnalysis/LocationsNote.ts
A location-scoped Container Analysis (Grafeas) note. Same shape as
Note, stored at
projects/{project}/locations/{location}/notes/{note}.
Location and note id are identity. Alchemy stamps ownership into
longDescription for list / nuke.
LocationsNote: Creating a Locations Note
Section titled “LocationsNote: Creating a Locations Note”const note = yield* GCP.ContainerAnalysis.LocationsNote("Authority", { location: "us-central1", shortDescription: "qa attestor", attestation: { hint: { humanReadableName: "QA" } },});LocationsOccurrence
Section titled “LocationsOccurrence”Source:
src/GCP/ContainerAnalysis/LocationsOccurrence.ts
A location-scoped Container Analysis (Grafeas) occurrence. Same shape as
Occurrence, stored at
projects/{project}/locations/{location}/occurrences/{occurrence}.
Location, noteName, and resourceUri are identity. Alchemy stamps
ownership into remediation for list / nuke.
LocationsOccurrence: Creating a Locations Occurrence
Section titled “LocationsOccurrence: Creating a Locations Occurrence”const note = yield* GCP.ContainerAnalysis.LocationsNote("Authority", { location: "us-central1", attestation: { hint: { humanReadableName: "QA" } },});const occurrence = yield* GCP.ContainerAnalysis.LocationsOccurrence( "Signed", { location: "us-central1", noteName: note.name, resourceUri: "https://example.com/image@sha256:abc", attestation: { serializedPayload: btoa("payload"), signatures: [ { publicKeyId: "https://example.com/keys/qa", signature: btoa("sig"), }, ], }, },);Source:
src/GCP/ContainerAnalysis/Note.ts
A project-scoped Container Analysis (Grafeas) note. Notes describe a type of analysis; occurrences attach a note to a resource such as a container image.
Notes have no labels field, so Alchemy stamps ownership into
longDescription for list / nuke. noteId is identity — changing it
replaces the note. Descriptions, related URLs, and kind payloads update
in place. Switching the analysis kind replaces the note.
Note: Creating a Note
Section titled “Note: Creating a Note”Attestation authority
const note = yield* GCP.ContainerAnalysis.Note("Authority", { shortDescription: "qa attestor", attestation: { hint: { humanReadableName: "QA" } },});Explicit id and related URL
const note = yield* GCP.ContainerAnalysis.Note("Authority", { noteId: "qa-attestor", shortDescription: "qa attestor", longDescription: "signs production images", relatedUrl: [{ url: "https://example.com/policy", label: "policy" }], attestation: { hint: { humanReadableName: "QA" } },});Note: Updating a Note
Section titled “Note: Updating a Note”Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.
const note = yield* GCP.ContainerAnalysis.Note("Authority", { shortDescription: "qa and staging attestor", attestation: { hint: { humanReadableName: "QA" } },});Occurrence
Section titled “Occurrence”Source:
src/GCP/ContainerAnalysis/Occurrence.ts
A project-scoped Container Analysis (Grafeas) occurrence. Occurrences attach a note to a concrete resource URI such as a container image digest.
The occurrence id is assigned by the API. noteName and resourceUri
are identity — changing either replaces the occurrence. Occurrences have
no labels field, so Alchemy stamps ownership into remediation for
list / nuke.
Occurrence: Creating an Occurrence
Section titled “Occurrence: Creating an Occurrence”const note = yield* GCP.ContainerAnalysis.Note("Authority", { attestation: { hint: { humanReadableName: "QA" } },});const occurrence = yield* GCP.ContainerAnalysis.Occurrence("Signed", { noteName: note.name, resourceUri: "https://example.com/image@sha256:abc", attestation: { serializedPayload: btoa("payload"), signatures: [ { publicKeyId: "https://example.com/keys/qa", signature: btoa("sig") }, ], },});Occurrence: Updating an Occurrence
Section titled “Occurrence: Updating an Occurrence”Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.
const occurrence = yield* GCP.ContainerAnalysis.Occurrence("Signed", { noteName: note.name, resourceUri: "https://example.com/image@sha256:abc", remediation: "rebuild from a patched base", attestation: { hint: { humanReadableName: "QA" } },});