Skip to main content
Cloud / Google Cloud / Products / Artifact Analysis - Vulnerability Scanning for Artifacts

Artifact Analysis - Vulnerability Scanning for Artifacts

Artifact Analysis scans container images and packages for vulnerabilities and stores the associated metadata. The service is the successor to Container Analysis.

Security
Pricing Model Pricing as published on the official Artifact Analysis pricing page
Availability Google Cloud service; see the official documentation for available locations
Data Sovereignty Artifact storage location follows your Artifact Registry configuration; see the official documentation
Reliability SLA as published by the provider SLA

What Is Artifact Analysis?

Artifact Analysis is Google Cloud’s vulnerability scanning and metadata management service for software artifacts. The documentation references Container Analysis as the product’s former name; the product was rebranded.

The service scans artifacts for known vulnerabilities and stores the associated metadata so it can be retrieved and evaluated later. Integration with Artifact Registry and Binary Authorization lets you feed the results into your software delivery process.

Core Capabilities

  • Vulnerability scanning for container artifacts
  • On-demand scanning and automated scanning as two operating modes
  • Storing and retrieving metadata for scanned artifacts
  • Support for multiple artifact types, including container images, Java packages, Go packages, and OS packages
  • Integration with Artifact Registry for artifact storage and with Binary Authorization for deployment security
  • Pub/Sub notifications about scan results
  • Fine-grained access control and operation inside a service perimeter (VPC Service Controls)

Typical Use Cases

Container security in the build pipeline: Images are scanned after the build, before they are rolled out to an environment.

Continuous inventory scanning: Automated scanning re-evaluates existing artifacts as new vulnerability information becomes available.

Deployment control: Combined with Binary Authorization, scan results form the basis for admission decisions.

Integration into security processes: Pub/Sub notifications carry results into alerting and ticketing systems.

Benefits

  • Managed service without your own scanner infrastructure
  • Coverage of container images plus language and OS packages
  • Direct coupling to Artifact Registry and Binary Authorization
  • Metadata storage for later evaluation and evidence
  • Operation inside a VPC service perimeter available

Working with innFactory

As a certified Google Cloud Partner, innFactory supports you with Artifact Analysis:

  • Supply chain design: embedding scanning into build and release processes
  • Policy design: connecting scan results to Binary Authorization for controlled deployments
  • Automation: wiring Pub/Sub notifications into your alerting and ticketing systems
  • Hardening: operating inside a VPC service perimeter and defining access control

Get in touch for a consultation on Artifact Analysis and software supply chain security.

Typical Use Cases

Vulnerability scanning of container images in Artifact Registry
Scanning of language packages and OS packages
Storing and retrieving artifact metadata
Securing deployments in combination with Binary Authorization

Technical Specifications

Artifact types Container images, Java packages, Go packages, and OS packages
Former name Container Analysis
Integrations Artifact Registry for artifact storage, Binary Authorization for deployment security, Pub/Sub notifications
Metadata Storing and retrieving metadata for scanned artifacts
Network security Securing Container Analysis in a service perimeter (VPC Service Controls)
Scanning modes On-demand scanning and automated scanning

Frequently Asked Questions

What is Artifact Analysis?

Artifact Analysis is Google Cloud's vulnerability scanning and metadata management service for artifacts. The documentation references Container Analysis as the product's former name.

Which artifact types are supported?

Supported types include container images, Java packages, Go packages, and OS packages. The complete list is in the official documentation.

What is the difference between on-demand and automated scanning?

Automated scanning evaluates artifacts without a separate trigger, while on-demand scanning is invoked explicitly, for example from a build pipeline. Both modes are documented.

How does Artifact Analysis relate to Binary Authorization?

Artifact Analysis integrates with Artifact Registry for artifact storage and with Binary Authorization for deployment security, so scan results can inform deployment decisions.

How am I notified about new findings?

Artifact Analysis supports Pub/Sub notifications, which lets you feed scan results into existing alerting and ticketing systems.

Can the service run inside a VPC service perimeter?

Yes. The documentation describes securing Container Analysis in a service perimeter for VPC-based deployments.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Ready to start with Artifact Analysis - Vulnerability Scanning for Artifacts?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation