Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Halaman ini menjelaskan cara melihat insight keamanan supply chain software untuk
revisi Cloud Run yang dipilih, dan memberikan detail singkat untuk membantu Anda
memahami hal yang diungkapkan informasi ini tentang postur keamanan
revisi.
Untuk mempelajari cara menggunakan Cloud Run dengan produk dan fitur Google Cloud lainnya untuk meningkatkan postur keamanan supply chain software Anda, lihat Keamanan supply chain software.
Sebelum memulai
Anda harus mengaktifkan Container Scanning API untuk pemindaian container.
Klik layanan yang Anda minati untuk membuka halaman Detail layanan.
Klik tab Revisi dan pilih revisi yang diinginkan.
Pada panel detail di sebelah kanan, klik tab Keamanan.
Cari bagian Insight keamanan. Bagian ini
menunjukkan rating kerentanan saat ini dan detail terkait lainnya untuk
revisi yang dipilih. Untuk informasi selengkapnya tentang detail ini, lihat bagian
Memahami insight keamanan
Memahami insight keamanan
Bagian Analisis keamanan menampilkan informasi berikut:
Supply-chain Levels for Software Artifacts (SLSA): Mengidentifikasi
tingkat kematangan proses build software Anda sesuai dengan spesifikasi
SLSA. Anda dapat menemukan detail selengkapnya di situs SLSA .
Kerentanan: Ringkasan kerentanan yang ditemukan di artefak Anda, dan nama gambar yang telah dipindai oleh Artifact Analysis. Anda dapat mengklik
nama gambar untuk melihat detail kerentanan.
Detail build: Detail build seperti builder dan link untuk melihat log.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-21 UTC."],[],[],null,["# View software supply chain security insights\n\nThis page describes how to view the software supply chain security insights for\na selected Cloud Run revision, and provides brief details to help you\nunderstand what this information reveals about the security posture of the\nrevision.\n\nTo learn how you can use Cloud Run with other Google Cloud products\nand features to improve the security posture of your\nsoftware supply chain, see [Software supply chain security](/software-supply-chain-security/docs/overview).\n\nBefore you begin\n----------------\n\nYou must enable Container Scanning API for container scanning.\n\n[Enable the Container Scanning API](https://console.cloud.google.com/apis/library/containerscanning.googleapis.com)\n\nRequired permissions\n--------------------\n\nTo view security insights, you need the following roles:\n\n- Artifact Analysis Occurrences Viewer\n- Cloud Run Viewer\n\nView security insights\n----------------------\n\n1. [Go to Cloud Run](https://console.cloud.google.com/run)\n\n2. Click the service you are interested in to open the **Service details** page.\n\n3. Click the **Revisions** tab and select the desired revision.\n\n4. In the details panel at the right, click the **Security** tab.\n\n5. Locate the **Security insights** section. This\n section shows the current vulnerability rating and other related details for\n the selected revision. For more information about these details, see the section\n [Understanding security insights](#understand-insights)\n\nUnderstanding security insights\n-------------------------------\n\nThe **Security insights** section displays the following information:\n\n- Supply-chain Levels for Software Artifacts (SLSA) level: Identifies the maturity level of your software build process in accordance with the SLSA specification. You can find more details at the [SLSA](https://slsa.dev/spec/v1.0/levels) website.\n- Vulnerabilities: An overview of any vulnerabilities found in your artifacts, and the name of the image that Artifact Analysis has scanned. You can click the image name to view vulnerability details.\n- Build details: Details of the build such as the builder and the link to view logs.\n- Build provenance: [Provenance](/software-supply-chain-security/docs/safeguard-builds#provenance) for the build.\n\nWhat's next\n-----------\n\n- For higher SLSA levels, consider setting up [continuous deployment](/run/docs/continuous-deployment-with-cloud-build).\n- For an example that deploys a Cloud Run service and leads you through the security insights for that service, see the [software supply chain security quickstart](/software-supply-chain-security/docs/quickstarts/deploy-run-view-security-insights)."]]