Quickstart for container images

This quickstart shows you how to pull a container image, manually scan it with the On-Demand Scanning API, and retrieve identified vulnerabilities. To follow this quickstart you will use Cloud Shell and an example Ubuntu image.

Before you begin

  1. Accede a tu cuenta de Google Cloud. Si eres nuevo en Google Cloud, crea una cuenta para evaluar el rendimiento de nuestros productos en situaciones reales. Los clientes nuevos también obtienen $300 en créditos gratuitos para ejecutar, probar y, además, implementar cargas de trabajo.
  2. En la página del selector de proyectos de Google Cloud Console, selecciona o crea un proyecto de Google Cloud.

  3. Asegúrate de que la facturación esté habilitada para tu proyecto de Cloud. Descubre cómo confirmar que tienes habilitada la facturación en un proyecto.

  4. Habilita la API On-Demand Scanning.

Download and scan an image

  1. Open a Cloud Shell in your project.

    This opens a terminal with all the required tools to follow this guide.

  2. Use docker to pull the latest Ubuntu image.

    docker pull ubuntu:latest
  3. Run the scan.

    gcloud artifacts docker images scan ubuntu:latest

    This triggers that scanning process and returns the scan name when finished:

    ✓ Scanning container image 
      ✓ Locally extracting packages and versions from local container image
      ✓ Remotely initiating analysis of packages and versions
      ✓ Waiting for analysis operation to complete [projects/my-project/locations/us/operations/1a6fd941-b997-4e5f-ba4f-6351f30e7dad]
    done: true
      '@type': type.googleapis.com/google.cloud.ondemandscanning.v1.AnalyzePackagesMetadata
      createTime: '2021-01-26T13:43:53.112123Z'
      resourceUri: ubuntu:latest
    name: projects/my-project/locations/us/operations/1a6fd941-b99f-4eaf-ba4f-6e5af30e7dad
      '@type': type.googleapis.com/google.cloud.ondemandscanning.v1.AnalyzePackagesResponse
      scan: projects/my-project/locations/us/scans/893c91ce-7fe6-4f1a-a69a-d6ca1b465160
  4. Use the scan name, the value of scan from the output, to fetch the scan results.

    gcloud artifacts docker images list-vulnerabilities \

Clean up

To avoid incurring charges to your Google Cloud account for the resources used in this quickstart, follow these steps.

If you created a new project for this guide, you can now delete the project.

