$npx skillfedfor your agent

grafeas

Grafeas API client library

With conditionsPyPI InternetReleased Aug 2026432.0K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — grafeas-1.24.0-py3-none-any.whl
v1.24.0 · released 2026-08-06 · Python >=3.10 · 5 runtime deps: google-api-core, google-auth, grpcio, proto-plus, protobuf

Yes, if you are working with Google Cloud Container Analysis. The library is actively maintained, has low install friction, carries a permissive Apache-2.0 license, and has no known vulnerabilities. It is the official client for the Grafeas API and is necessary to interact with Container Analysis metadata from Python. Not relevant if you are not using Google Cloud or Container Analysis.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python >= 3.10 and Google Cloud authentication credentials configured (via GOOGLE_APPLICATION_CREDENTIALS or Application Default Credentials).
  • Low install friction with a pure-wheel distribution.
  • Actively maintained with a release 8 days old and recent commits.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for most projects.

last release 2026-08-06 (8 days) · last repo commit 2026-08-14 · 5,373 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 431,957 downloads/mo, #6,712 on PyPI

Verify before relying

pip install grafeas

from google.cloud import grafeas_v1

client = grafeas_v1.GrafeasClient()
# Query metadata from Container Analysis
  • Whether the library supports offline use or requires active Google Cloud connectivity for all operations.
  • Performance characteristics when querying large volumes of artifact metadata.
  • Whether Container Analysis API must be explicitly enabled in a Google Cloud project before use.
Same gist for agents: .md · .json

What it is and what it does

Grafeas is Google's official Python client for the Grafeas API, an implementation that stores and enables querying of critical metadata about software artifacts. It wraps the Container Analysis service on Google Cloud Platform, allowing developers to programmatically access, query, and retrieve artifact metadata. The library is built on standard Google Cloud infrastructure (google-api-core, google-auth, grpcio, proto-plus, protobuf) and integrates with gRPC for communication.

The package is intended for developers working with Google Cloud who need to interact with artifact metadata at scale—for example, querying vulnerability data, build provenance, or deployment information about container images and other software artifacts. It requires Python 3.10 or later and assumes the user has a Google Cloud project with Container Analysis enabled and proper authentication configured.

Use it for

  • Query vulnerability and security metadata for container images stored in Google Cloud.
  • Retrieve build provenance and deployment information about software artifacts.
  • Integrate artifact metadata queries into CI/CD pipelines for compliance and auditing.
  • Programmatically access critical metadata about all software artifacts in a project.
  • Build custom dashboards or tools that analyze artifact metadata from Container Analysis.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are working with Google Cloud Container Analysis.

The library is actively maintained, has low install friction, carries a permissive Apache-2.0 license, and has no known vulnerabilities. It is the official client for the Grafeas API and is necessary to interact with Container Analysis metadata from Python. Not relevant if you are not using Google Cloud or Container Analysis.

Install

grafeas on PyPI

Before you install

Low install friction with a pure-wheel distribution. Actively maintained with a release 8 days old and recent commits. Depends on standard Google Cloud libraries (google-api-core, google-auth, grpcio, proto-plus, protobuf).

Requires Python >= 3.10 and Google Cloud authentication credentials configured (via GOOGLE_APPLICATION_CREDENTIALS or Application Default Credentials).

License in practice

Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for most projects.

Quickstart

pip install grafeas

from google.cloud import grafeas_v1

client = grafeas_v1.GrafeasClient()
# Query metadata from Container Analysis

Verify before relying

  • Whether the library supports offline use or requires active Google Cloud connectivity for all operations.
  • Performance characteristics when querying large volumes of artifact metadata.
  • Whether Container Analysis API must be explicitly enabled in a Google Cloud project before use.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
5 packages
google-api-coregoogle-authgrpcioproto-plusprotobuf
MaintenanceActively maintained 8 days since the last release
Last repo commit
First released
Downloads431,957 / month, #6,712 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Internet

Evidence: grafeas-1.24.0-py3-none-any.whl

Tags

Capabilities
grafeas api clientcontainer analysis metadatasoftware artifact metadata querygoogle cloud grafeasartifact metadata storagecontainer metadata retrievalgrafeas python client
Topics
google-cloudartifact-metadatacontainer-analysis

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “grafeas api client”

Give your agent the search over MCP, or paste the wish link into any chat.

More Internet packages

botocore Worth it
PyPI · Internet · released Aug 2026

Botocore provides low-level, data-driven access to Amazon Web Services APIs, serving as the foundation for the AWS CLI and boto3 libraries.

Install it if you need programmatic access to AWS services.

permissive licensepure Python · 3.10+
1.5Bdownloads / mo
aiobotocore Worth it
PyPI · Internet · released Aug 2026

Provides an async client for AWS services using botocore and aiohttp, allowing you to call AWS APIs asynchronously within asyncio-based applications.

Install it if you need to call AWS services from async Python code; it is the standard way to do so.

Apache-2.0pure Python · 3.10+
1.2Bdownloads / mo
pydantic Worth it
PyPI · Python Modules · released May 2026

Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.

MITpure Python · 3.9+
1.1Bdownloads / mo
filelock Worth it
PyPI · Libraries · released Aug 2026

Provides a platform-independent file locking mechanism to coordinate access to files across processes and threads.

MITpure Python · 3.10+
717.1Mdownloads / mo
fastapi Worth it
PyPI · Software Development · released Jul 2026

FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.

MITpure Python · 3.10+
568.6Mdownloads / mo
googleapis-common-protos Worth it
PyPI · Internet · released Aug 2026

Provides common Protocol Buffer message definitions used across Google Cloud APIs, enabling Python clients to interact with Google services.

Apache-2.0pure Python · 3.10+
513.7Mdownloads / mo

See also google-cloud-containeranalysis · google-cloud-artifact-registry · google-cloud-container · google-cloud-resource-manager · google-cloud-bigquery-storage · google-analytics-data · google-cloud-monitoring · google-cloud-filestore · google-cloud-billing · google-cloud-bigquery-logging