Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
github.com/GoogleCloudPlatform/cloud-builders
This repository contains source code for official builders used with the Google Cloud Build API.
Pre-built images are available at gcr.io/cloud-builders/...
and include:
aactl
: runs the aactl toolbazel
: runs the bazel toolcurl
: runs the curl tooldocker
: runs the docker tooldotnet
: run the dotnet toolgcloud
: runs the gcloud toolgcs-fetcher
: efficiently fetches objects from Google Cloud Storagegit
: runs the git toolgke-deploy
: deploys an application to a Kubernetes cluster, following Google's recommended best practicesgo
: runs the go toolgradle
: runs the gradle toolgsutil
: runs the gsutil tooljavac
: runs the javac toolkubectl
: runs the kubectl toolmvn
: runs the maven toolnpm
: runs the npm tooltwine
: runs the twine toolwget
: runs the wget toolyarn
: runs the yarn toolBuilders contributed by the public are available in the Cloud Builders Community repo.
Each builder includes a cloudbuild.yaml
that will push your images to Artifact
Registry. To build with this default cloudbuild.yaml
,
you will need to first create an Artifact Registry repository with gcr.io domain support.
To file issues and feature requests against these builder images, create an issue in this repo. If you are experiencing an issue with the Cloud Build service or have a feature request, e-mail google-cloud-dev@googlegroups.com or see our Getting support documentation.
Most of the tools in this repo are also available in community-supported publicly available repositories. Such repos also generally support multiple versions and platforms, available by tag.
The following community-supported images are compatible with the
hosted Cloud Build service and function well as build steps; note that
some will require that you specify an entrypoint
for the image. Additional
details regarding each alternative official image are available in the README.md
for the corresponding Cloud Builder.
docker
supports tagged docker versions across multiple platformsgcr.io/google.com/cloudsdktool/cloud-sdk
includes multiple entrypoints:
node
includes these entrypoints:
microsoft/dotnet:sdk
includes
dotnet
: runs the dotnet toolgcr.io/cloud-marketplace-containers/google/bazel
is provided by the bazel team and runs the bazel
toolcurl
is packaged in:
launcher.gcr.io/google/ubuntu1604
curlimages/curl
is community-supportedgolang
is provided by the Go team and runs the go
toolGoogle announced on May 15 2023 that Container Registry has been deprecated and is superseded by Artifact Registry. The deprecation won't affect the use of official cloud builder images. Artifact Registry automatically redirects gcr.io requests for Container Registry hosts to corresponding Artifact Registry repositories.
You may have already noticed that most of the images in this repo now provide notices to the
above alternative images. For the hosted Cloud Build service, we are formulating plans
surrounding both improved support for existing cloud-builder
images and documentation for
alternative community-supported images that may be more appropriate for some users. Both this
page and the related open issues
will be updated with details soon.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.