Skip to content

GCP.SecureSourceManager reference

Source: src/GCP/SecureSourceManager/RepositoriesBranchRule.ts

A Secure Source Manager branch protection rule.

Changing branchRuleId, repository, or location replaces the rule. Pattern, flags, checks, and annotations update in place. Ownership for list / nuke is stamped into annotations.

RepositoriesBranchRule: Creating a Branch Rule

Section titled “RepositoriesBranchRule: Creating a Branch Rule”

Protect the default branch

const rule = yield* GCP.SecureSourceManager.RepositoriesBranchRule("Main", {
repository: repo.name,
includePattern: "main",
requirePullRequest: true,
minimumApprovalsCount: 1,
});

Named rule with annotations

const rule = yield* GCP.SecureSourceManager.RepositoriesBranchRule("Main", {
repository: repo.name,
branchRuleId: "protect-main",
includePattern: "main",
requireCommentsResolved: true,
annotations: { env: "prod" },
});

RepositoriesBranchRule: Updating a Branch Rule

Section titled “RepositoriesBranchRule: Updating a Branch Rule”

Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.

const rule = yield* GCP.SecureSourceManager.RepositoriesBranchRule("Main", {
repository: repo.name,
includePattern: "main",
requirePullRequest: true,
minimumApprovalsCount: 2,
annotations: { env: "prod", team: "platform" },
});

Source: src/GCP/SecureSourceManager/RepositoriesHook.ts

A Secure Source Manager repository webhook.

Changing hookId, repository, or location replaces the hook. Target URI, events, disabled flag, and push options update in place. Ownership for list / nuke is stamped into targetUri query parameters (hooks have no labels field).

Push webhook

const hook = yield* GCP.SecureSourceManager.RepositoriesHook("Notify", {
repository: repo.name,
targetUri: "https://example.com/hooks/ssm",
events: ["PUSH"],
});

Named hook with a branch filter

const hook = yield* GCP.SecureSourceManager.RepositoriesHook("Notify", {
repository: repo.name,
hookId: "prod-push",
targetUri: "https://example.com/hooks/ssm",
events: ["PUSH", "PULL_REQUEST"],
pushOption: { branchFilter: "main" },
});

Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.

const hook = yield* GCP.SecureSourceManager.RepositoriesHook("Notify", {
repository: repo.name,
targetUri: "https://example.com/hooks/ssm-v2",
events: ["PUSH"],
disabled: true,
});

Source: src/GCP/SecureSourceManager/RepositoriesIssue.ts

A Secure Source Manager issue.

Issue ids are server-assigned. Changing issueId or repository replaces the issue. Title and body update in place. Ownership for list / nuke is stamped into the body (issues have no labels field).

const issue = yield* GCP.SecureSourceManager.RepositoriesIssue("Bug", {
repository: repo.name,
title: "webhook retries 500s",
body: "hooks retry forever on 500",
});

Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.

const issue = yield* GCP.SecureSourceManager.RepositoriesIssue("Bug", {
repository: repo.name,
title: "webhook retries 5xx",
body: "cap retries at 8",
});

Source: src/GCP/SecureSourceManager/RepositoriesIssuesIssueComment.ts

A comment on a Secure Source Manager issue.

Comment ids are server-assigned. Changing commentId or issue replaces the comment. Body updates in place. Ownership for list / nuke is stamped into the body (comments have no labels field).

RepositoriesIssuesIssueComment: Creating an Issue Comment

Section titled “RepositoriesIssuesIssueComment: Creating an Issue Comment”
const comment = yield* GCP.SecureSourceManager.RepositoriesIssuesIssueComment(
"Note",
{
issue: issue.name,
body: "reproduced on main",
},
);

RepositoriesIssuesIssueComment: Updating an Issue Comment

Section titled “RepositoriesIssuesIssueComment: Updating an Issue Comment”

Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.

const comment = yield* GCP.SecureSourceManager.RepositoriesIssuesIssueComment(
"Note",
{
issue: issue.name,
body: "reproduced on release",
},
);

RepositoriesPullRequestsPullRequestComment

Section titled “RepositoriesPullRequestsPullRequestComment”

Source: src/GCP/SecureSourceManager/RepositoriesPullRequestsPullRequestComment.ts

A comment on a Secure Source Manager pull request.

Comment ids are server-assigned. Changing commentId or pullRequest replaces the comment. Body updates in place. Ownership for list / nuke is stamped into the comment body (comments have no labels field). Create a general comment, a review, or a code reply — batch review-plus-code threads use the distilled batch-create API.

RepositoriesPullRequestsPullRequestComment: Creating a Pull Request Comment

Section titled “RepositoriesPullRequestsPullRequestComment: Creating a Pull Request Comment”
const comment =
yield* GCP.SecureSourceManager.RepositoriesPullRequestsPullRequestComment(
"Note",
{
pullRequest: pullRequest.name,
comment: { body: "looks good" },
},
);

RepositoriesPullRequestsPullRequestComment: Updating a Pull Request Comment

Section titled “RepositoriesPullRequestsPullRequestComment: Updating a Pull Request Comment”

Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.

const comment =
yield* GCP.SecureSourceManager.RepositoriesPullRequestsPullRequestComment(
"Note",
{
pullRequest: pullRequest.name,
comment: { body: "looks good after the rebase" },
},
);