google-cloud-containeranalysis
Google Cloud Containeranalysis API client library
Decision gist · record as of 2026-08-14
Yes, if you are working with Google Cloud container infrastructure and need programmatic access to artifact metadata or vulnerability scanning results. The library is actively maintained, has no known vulnerabilities, supports current Python versions, and carries a permissive license. Install only if you have a Google Cloud project with Container Analysis enabled and a clear use case for querying artifact metadata or scanning data.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Google Cloud project setup, billing enabled, Container Analysis API enabled, and authentication credentials configured (service account or application default credentials).
- Low install friction with a pure-Python wheel distribution.
- Actively maintained as of 8 days ago with recent commits and production-stable status.
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing commercial use, modification, and distribution with minimal restrictions—suitable for most projects.
last release 2026-08-06 (8 days) · last repo commit 2026-08-14 · 5,373 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 102,262 downloads/mo, #12,876 on PyPI
Alternatives
Verify before relying
pip install google-cloud-containeranalysis
from google.cloud import containeranalysis_v1
client = containeranalysis_v1.ContainerAnalysisClient()
# Query artifact metadata or vulnerability information- Specific API methods and their signatures beyond the client instantiation pattern.
- Performance characteristics when querying large artifact metadata sets.
- Integration complexity with existing Artifact Registry or GKE deployments.
What it is and what it does
This is the official Python client for Google Cloud Container Analysis, a service that stores and retrieves metadata about software artifacts and integrates with vulnerability scanning in Artifact Registry and GKE. It implements the Grafeas API standard, providing a structured way to query and manage artifact metadata across your container infrastructure.
The library wraps Google Cloud's gRPC APIs and handles authentication, serialization, and connection management. It's designed for developers building container security workflows, artifact governance systems, or vulnerability management tools that need programmatic access to container metadata and scanning results. Installation is straightforward for modern Python environments (3.10+), though it requires prior setup of a Google Cloud project with the Container Analysis service enabled.
Use it for
- Query vulnerability scan results from Artifact Registry to build custom security dashboards or compliance reports.
- Retrieve artifact metadata and attestations for policy enforcement in CI/CD pipelines.
- Integrate GKE runtime vulnerability scanning data into centralized security monitoring systems.
- Automate artifact governance by querying and filtering container images by metadata attributes.
- Build custom tooling to correlate container images with their known vulnerabilities across deployments.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are working with Google Cloud container infrastructure and need programmatic access to artifact metadata or vulnerability scanning results.
The library is actively maintained, has no known vulnerabilities, supports current Python versions, and carries a permissive license. Install only if you have a Google Cloud project with Container Analysis enabled and a clear use case for querying artifact metadata or scanning data.
Install
google-cloud-containeranalysis on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Actively maintained as of 8 days ago with recent commits and production-stable status. Requires Python >= 3.10 and depends on standard Google Cloud libraries (google-api-core, google-auth, protobuf, grpcio).
Requires Google Cloud project setup, billing enabled, Container Analysis API enabled, and authentication credentials configured (service account or application default credentials).
License in practice
Licensed under Apache-2.0 (permissive), allowing commercial use, modification, and distribution with minimal restrictions—suitable for most projects.
Quickstart
pip install google-cloud-containeranalysis
from google.cloud import containeranalysis_v1
client = containeranalysis_v1.ContainerAnalysisClient()
# Query artifact metadata or vulnerability information
Verify before relying
- Specific API methods and their signatures beyond the client instantiation pattern.
- Performance characteristics when querying large artifact metadata sets.
- Integration complexity with existing Artifact Registry or GKE deployments.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 7 packagesgoogle-api-coregoogle-authgrafeasgrpcioproto-plusprotobufgrpc-google-iam-v1 |
| Maintenance | Actively maintained 8 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 102,262 / month, #12,876 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Internet |
Evidence: google_cloud_containeranalysis-2.22.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “artifact metadata querying”
- google-cloud-containeranalysisPython client library for Google Cloud Container Analysis API,…
- grafeasPython client library for the Grafeas API, enabling querying and…
- dohq-artifactoryA Python library that provides pathlib-like access to JFrog…
Give your agent the search over MCP, or paste the wish link into any chat.
More Internet packages
Botocore provides low-level, data-driven access to Amazon Web Services APIs, serving as the foundation for the AWS CLI and boto3 libraries.
Install it if you need programmatic access to AWS services.
Provides an async client for AWS services using botocore and aiohttp, allowing you to call AWS APIs asynchronously within asyncio-based applications.
Install it if you need to call AWS services from async Python code; it is the standard way to do so.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides a platform-independent file locking mechanism to coordinate access to files across processes and threads.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides common Protocol Buffer message definitions used across Google Cloud APIs, enabling Python clients to interact with Google services.
See also grafeas · google-cloud-artifact-registry · google-cloud-container · google-cloud-resource-manager · azure-containerregistry · google-cloud-monitoring · google-cloud-run · google-cloud-bigquery-logging · google-cloud-service-usage · google-cloud-build