Skip to content

Improve GCP Artifact Registry and org policy gates#1379

Open
MAUROCERON wants to merge 1 commit into
UnitOneAI:mainfrom
MAUROCERON:improve/gcp-artifact-orgpolicy-1111
Open

Improve GCP Artifact Registry and org policy gates#1379
MAUROCERON wants to merge 1 commit into
UnitOneAI:mainfrom
MAUROCERON:improve/gcp-artifact-orgpolicy-1111

Conversation

@MAUROCERON
Copy link
Copy Markdown

Summary

Implements #1111 by adding GCP Artifact Registry and organization-policy drift evidence gates to gcp-review, plus bounded handling for hybrid service-account key exceptions and sensitive-workload Confidential VM evidence.

Changes

  • Adds required context for effective org/folder/project policy exports, Artifact Registry repository/scanning evidence, remote upstreams, image digests, and sensitive VM workload classification.
  • Expands severity examples and common pitfalls for Artifact Registry coverage, org-policy inheritance drift, validated hybrid service-account key exceptions, and Confidential VM applicability.
  • Adds a benchmark checklist gate for validated hybrid service-account key exceptions under CIS 1.4.
  • Adds an Organization Policy Drift Evidence Gate requiring effective policy evidence and lower-scope override checks.
  • Adds Artifact Registry vulnerability scanning and remote repository upstream evidence under Section 5.
  • Adds Confidential VM evidence guidance for sensitive memory workloads.
  • Adds an edge-case fixture covering hybrid SA keys, Artifact Registry scanning, remote repositories, project-level org policy override, and Confidential Computing gaps.

Validation

  • Generated SKILL.md and benchmark-checklist.md from upstream main to avoid carrying unrelated local BigQuery changes.
  • Markdown fence balance checked for all changed files.
  • Remote branch content fetched and checked for marker presence, no encoding corruption, and no BigQuery fine-grained-access carryover.
  • Duplicate check: issue [REVIEW] gcp-review: add Artifact Registry vulnerability scanning and Organization Policy 'Drift' gates #1111 has no comments and no visible PR matching 1111 OR Artifact Registry vulnerability scanning Organization Policy Drift gcp-review before this submission.
  • Official references checked with HTTP 200: Artifact Registry vulnerability scanning, Artifact Registry remote repositories, Organization Policy overview, Organization Policy constraints, and Confidential VM overview.

Bounty Info

  • I have read and agree to the CONTRIBUTING.md bounty terms.
  • Preferred payment method: Payment details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant