Back to controls

Ensure Artifact Registry Docker repositories enforce immutable tags

### Overview

Category

Controls

Medium

Applies to

Google Cloud

Coverage

1 queries

Asset types

1 covered

Overview

Overview

Mutable image tags make it easier to overwrite trusted image references and weaken software supply-chain controls. For production Docker repositories, immutable tags help preserve provenance, improve rollback safety, and reduce the risk of unreviewed image swaps.

Remediation guidance

From Google Cloud Console

  1. Open the affected Artifact Registry repository.
  2. Edit repository settings.
  3. Enable immutable image tags for Docker repositories.
  4. Save and update deployment pipelines to publish unique version tags or digests.

Immutable tags are a common software supply-chain baseline for production registries.

Query logic

These are the stored checks tied to this control.

Artifact Registry Docker repositories with mutable tags

Connectors

Google Cloud

Covered asset types

ArtifactRegistryRepository

Expected check: eq []

{ artifactRegistryRepositories(where: { format: "DOCKER", dockerImmutableTags: false }) { ...AssetFragment } }
Cyscale Logo
Cyscale is an agentless cloud-native application protection platform (CNAPP) that automates the contextual analysis of cloud misconfigurations, vulnerabilities, access, and data, to provide an accurate and actionable assessment of risk.

Stay connected

Receive new blog posts and product updates from Cyscale

By clicking Subscribe, I agree to Cyscale’s Privacy Policy


© 2026 Cyscale Limited

LinkedIn icon
Twitter icon
Facebook icon
crunch base icon
angel icon