Skip to content

GCP.WebSecurityScanner reference

Source: src/GCP/WebSecurityScanner/ScanConfig.ts

A Web Security Scanner scan configuration.

Scan config ids are assigned by Google and scan configs have no labels field, so Alchemy tracks a config only through the name recorded in state; a config read without prior state is reported as unowned. Display name, starting URLs, QPS, user agent, blacklist, schedule, authentication, platforms, export, risk, and scan flags update in place. Changing scanConfigId replaces the config.

Starting URLs must belong to the project — a reserved Compute IP, App Engine (https://PROJECT.appspot.com), Cloud Run, or Cloud Functions.

Scan a reserved Compute IP

const ip = yield* GCP.Compute.Address("Target", {
region: "us-central1",
});
const scan = yield* GCP.WebSecurityScanner.ScanConfig("Site", {
displayName: "public site",
startingUrls: [Output.interpolate`http://${ip.address}`],
targetPlatforms: ["COMPUTE"],
exportToSecurityCommandCenter: "DISABLED",
});

Low-risk scan with excluded paths

const scan = yield* GCP.WebSecurityScanner.ScanConfig("Site", {
displayName: "public site",
startingUrls: ["https://my-app-uc.a.run.app/"],
targetPlatforms: ["CLOUD_RUN"],
maxQps: 5,
riskLevel: "LOW",
userAgent: "CHROME_LINUX",
blacklistPatterns: ["https://my-app-uc.a.run.app/logout"],
ignoreHttpStatusErrors: true,
exportToSecurityCommandCenter: "DISABLED",
});
// Same logical id as before; only the changed props differ.
const scan = yield* GCP.WebSecurityScanner.ScanConfig("Site", {
displayName: "public site v2",
startingUrls: [Output.interpolate`http://${ip.address}`],
targetPlatforms: ["COMPUTE"],
maxQps: 10,
exportToSecurityCommandCenter: "DISABLED",
});