Skip to content

Document verified container image lineage permissions - #453

Open
maximelb wants to merge 5 commits into
masterfrom
feat/207-native-lineage-docs
Open

maximelb wants to merge 5 commits into
masterfrom
feat/207-native-lineage-docs

Conversation

@maximelb

Copy link
Copy Markdown
Contributor

Summary

  • Explain the read-only Artifact Analysis occurrence role for verified Cloud Build image provenance, including the image project scope.
  • Document GitHub App Attestations: Read-only for new and existing installations.
  • Clarify that unsigned source claims remain asserted.

Validation

  • mkdocs build --strict passed.
  • Reviewed the diff for private identifiers and credentials; none included.

This is a public documentation PR and is left open for maintainer merge.

@maximelb

Copy link
Copy Markdown
Contributor Author

Adversarial self-review of pristine commit ee3ef43: checked role scope, installation upgrade instructions, links, and public-content boundary. Found and fixed one ambiguous placement of the GCP registry-reader bullets in follow-up commit ee3ef43. No open findings. mkdocs build --strict passes. Leaving this public PR for maintainer merge.

lcbill
lcbill previously approved these changes Sep 27, 2026
lcbill
lcbill previously approved these changes Sep 27, 2026
lcbill
lcbill previously approved these changes Sep 27, 2026
@maximelb

Copy link
Copy Markdown
Contributor Author

Adversarial self-review from pristine git archive e7e005f: checked the GCP role and image/occurrence project scope, existing App installation permission acceptance, G2 owned/third-party/unknown semantics, links, and public content for internal project names or customer data. mkdocs build --strict passes on the exact head. No open findings. This public PR remains for Maxime to merge.

@maximelb

Copy link
Copy Markdown
Contributor Author

Adversarial self-review of exact head f707d9c3 from a pristine git archive extraction, compared with the reviewed prior head and the public setup flow. The final edit resolves an ambiguous permission sentence: registry pull access controls image scanning, while roles/containeranalysis.occurrences.viewer controls Cloud Build provenance verification. The grant example still targets the image/occurrence project and the connected service account. I checked the changed pages for internal project names, tenant identifiers and PII; none are present. git diff --check passes. No open correctness issue. Final exact-head documentation CI is running.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants