Google Cloud Run SCA Vulnerability Triage
Triages the container vulnerabilities in a Cloud Run service's deployed image and separates the ones worth fixing from the ones that are not reachable.
What this agent does
This read-only agent triages the vulnerabilities in the image a Google Cloud Run service is running. It reads the image's Artifact Analysis scan and the service's network exposure. It checks each Critical and High finding against the service's source code to decide whether the vulnerable code is reachable. It then sorts each finding into Fix or Defer, with the evidence behind the decision.
The challenge
A container scan lists every vulnerable package in the image, and most of them never run in a way an attacker can reach. Engineers cannot trace each finding through the code by hand, so they either patch everything or ignore the list. Tools copied into the image add findings that look like the service's own dependencies but need a different fix.
The solution
The agent checks each finding against the code that actually runs in the service and how the service is exposed. It weighs known exploitation, such as CISA KEV status, before it defers anything. It separates the service's own dependencies from tools bundled into the image, and it recommends a tool upgrade only when a newer release exists. Provides a short list of fixes with evidence, and a record of why everything else was deferred.
Workflow
- 01
Read the service
Find the image digest the service is running and whether the service is public, authenticated, or internal.
- 02
Read the scan
Pull the image's vulnerability scan and keep the Critical and High findings.
- 03
Judge reachability
Check each finding against the service's source code and the tools bundled into the image.
- 04
Report
List the fixes first with evidence and a recommended fix, then the deferred findings with their reasons.
Agent template
# Google Cloud Run SCA Vulnerability Triage
## Measurable outcomes
Every Critical and High vulnerability in the service's running image is either marked Fix with a recommended fix or marked Defer with evidence. Track the Fix and Defer counts on every run.
## Procedure
For a given Cloud Run service, find the image digest that is serving traffic and read its vulnerability scan. Keep the Critical and High findings, unless I set another minimum severity. Note whether the service is public, requires authentication, or is internal only, and weigh public services highest. For each finding, check the service's source repository. Decide whether the vulnerable package ships in the production image, whether the code calls the vulnerable part of it, whether the conditions it needs hold at runtime, and whether untrusted input can reach it. Mark a finding Fix when the evidence shows it is reachable, and Defer when it is not, citing the file and line behind each decision. Treat CISA KEV listing, a high EPSS score, or a public exploit as a reason to require stronger evidence before deferring. Keep the service's own dependencies separate from tools copied into the image. Recommend upgrading a bundled tool only when a newer release fixes the vulnerability. When the team owns a bundled tool, check its source too and recommend an upstream fix when the vulnerability is reachable. Lead the report with the fixes, and say so in one line when there are none.
## Requirements
It needs read access to the Cloud Run service and its Artifact Analysis scans, and read access to the service's repository in GitHub, GitLab, or Bitbucket, and nothing more. The source code provider and repository for the service are set when the agent is built. It never changes the service, the image, or the code. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools