手动扫描 Go 软件包

借助 On-Demand Scanning API,您可以扫描存储在本地计算机上或 Artifact Registry 中的映像。您可以在 CI/CD 流水线中使用 On-Demand Scanning 扫描映像,以查找系统漏洞和 Go 软件包漏洞,然后再决定是否将其存储在注册数据库中。如需了解价格信息,请参阅 价格页面

本页面介绍了如何手动扫描容器映像,以查找系统漏洞和 Go 软件包漏洞。

准备工作

  1. 登录您的 Google Cloud 账号。如果您是 Google Cloud的新用户, 请创建账号,以评估我们的产品在 实际场景中的表现。新客户还可获享 $300 赠金,用于 运行、测试和部署工作负载。
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  3. Verify that billing is enabled for your Google Cloud project.