What Is Artifact Analysis?
Artifact Analysis is Google Cloud’s vulnerability scanning and metadata management service for software artifacts. The documentation references Container Analysis as the product’s former name; the product was rebranded.
The service scans artifacts for known vulnerabilities and stores the associated metadata so it can be retrieved and evaluated later. Integration with Artifact Registry and Binary Authorization lets you feed the results into your software delivery process.
Core Capabilities
- Vulnerability scanning for container artifacts
- On-demand scanning and automated scanning as two operating modes
- Storing and retrieving metadata for scanned artifacts
- Support for multiple artifact types, including container images, Java packages, Go packages, and OS packages
- Integration with Artifact Registry for artifact storage and with Binary Authorization for deployment security
- Pub/Sub notifications about scan results
- Fine-grained access control and operation inside a service perimeter (VPC Service Controls)
Typical Use Cases
Container security in the build pipeline: Images are scanned after the build, before they are rolled out to an environment.
Continuous inventory scanning: Automated scanning re-evaluates existing artifacts as new vulnerability information becomes available.
Deployment control: Combined with Binary Authorization, scan results form the basis for admission decisions.
Integration into security processes: Pub/Sub notifications carry results into alerting and ticketing systems.
Benefits
- Managed service without your own scanner infrastructure
- Coverage of container images plus language and OS packages
- Direct coupling to Artifact Registry and Binary Authorization
- Metadata storage for later evaluation and evidence
- Operation inside a VPC service perimeter available
Working with innFactory
As a certified Google Cloud Partner, innFactory supports you with Artifact Analysis:
- Supply chain design: embedding scanning into build and release processes
- Policy design: connecting scan results to Binary Authorization for controlled deployments
- Automation: wiring Pub/Sub notifications into your alerting and ticketing systems
- Hardening: operating inside a VPC service perimeter and defining access control
Get in touch for a consultation on Artifact Analysis and software supply chain security.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Artifact Analysis?
Artifact Analysis is Google Cloud's vulnerability scanning and metadata management service for artifacts. The documentation references Container Analysis as the product's former name.
Which artifact types are supported?
Supported types include container images, Java packages, Go packages, and OS packages. The complete list is in the official documentation.
What is the difference between on-demand and automated scanning?
Automated scanning evaluates artifacts without a separate trigger, while on-demand scanning is invoked explicitly, for example from a build pipeline. Both modes are documented.
How does Artifact Analysis relate to Binary Authorization?
Artifact Analysis integrates with Artifact Registry for artifact storage and with Binary Authorization for deployment security, so scan results can inform deployment decisions.
How am I notified about new findings?
Artifact Analysis supports Pub/Sub notifications, which lets you feed scan results into existing alerting and ticketing systems.
Can the service run inside a VPC service perimeter?
Yes. The documentation describes securing Container Analysis in a service perimeter for VPC-based deployments.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
