Skip to content

Add GCP Artifact Registry and org policy evidence gates#1136

Open
alan747271363-art wants to merge 1 commit into
UnitOneAI:mainfrom
alan747271363-art:improve/gcp-artifact-org-policy-evidence
Open

Add GCP Artifact Registry and org policy evidence gates#1136
alan747271363-art wants to merge 1 commit into
UnitOneAI:mainfrom
alan747271363-art:improve/gcp-artifact-org-policy-evidence

Conversation

@alan747271363-art
Copy link
Copy Markdown

Summary

  • add GCP organization policy inheritance/drift evidence so project-level overrides are not treated as compliant without parent policy context
  • add Artifact Registry / Artifact Analysis scanning gates for repository inventory, Container Scanning API enablement, repository-level scan settings, and remote repository upstream review
  • add Confidential VM applicability evidence before scoring sensitive workloads
  • add a documented hybrid service-account-key exception gate so user-managed keys are not blanket-classified without role, rotation, storage, owner, and migration evidence

Scope notes

Addresses #1111. This stays scoped to gcp-review and uses existing CIS sections plus supplemental Google Cloud evidence rather than inventing new benchmark IDs.

Official references used:

Validation

Bounty

Skill Improvement / Improver candidate. Payment details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant