Overview
Overview
Mutable image tags make it easier to overwrite trusted image references and weaken software supply-chain controls. For production Docker repositories, immutable tags help preserve provenance, improve rollback safety, and reduce the risk of unreviewed image swaps.
Remediation guidance
From Google Cloud Console
- Open the affected Artifact Registry repository.
- Edit repository settings.
- Enable immutable image tags for Docker repositories.
- Save and update deployment pipelines to publish unique version tags or digests.
Immutable tags are a common software supply-chain baseline for production registries.
Query logic
These are the stored checks tied to this control.
Artifact Registry Docker repositories with mutable tags
Connectors
Covered asset types
Expected check: eq []
{ artifactRegistryRepositories(where: { format: "DOCKER", dockerImmutableTags: false }) { ...AssetFragment } }
Google Cloud