Google Cloud expands vulnerabi... Note

Google Cloud expands vulnerability detection for Artifact Registry using OSV

DevOps teams can now improve their image and container security by utilizing Google-grade vulnerability scanning, which offers expanded open-source coverage through Google Cloud Platform's integrated security tools, including Artifact Analysis. Artifact Analysis has recently expanded its scanning coverage to eight additional language packages, four operating systems, and two extensively utilized base images. This enhanced coverage was achieved by integrating Artifact Analysis with the Open Source Vulnerabilities (OSV) platform and database, providing industry-leading insights into open source vulnerabilities. With these updates, customers can now successfully scan the vast majority of the images they push to Artifact Registry, detecting and reporting known vulnerabilities. Artifact Analysis pulls vulnerability information directly from OSV, which is the only open source, distributed vulnerability database that gets information directly from open source practitioners. OSV's database provides a consistent, high-quality database of vulnerabilities from authoritative sources, ensuring accurate information to reliably match software dependencies to known vulnerabilities. The OSV database has increased its total coverage to 28 language and OS ecosystems over the past three years, including industry leaders such as GitHub and Ubuntu. As a result of OSV's expansion, scanners like Artifact Analysis now alert users to higher quality vulnerability information across a broader set of ecosystems. Existing Artifact Registry scanning customers will immediately benefit from this expanded coverage, and vulnerability findings will continue to be available in the Artifact Registry UI, Container Analysis API, and via pub/sub. In 2025, Artifact Analysis capabilities will be integrated with Google Cloud's Security Command Center, allowing customers to maintain a more comprehensive vulnerability management program.