Conversation
Add the tool-reference page for the new Google Cloud asset connector (English plus de/es/fr/ja translations), and list it in the upstream connector index and the asset-connector call-outs so it shows up next to Google Cloud SCC.
- The ACTIVE filter applies to folders and projects both; reword the sentence so it does not read as projects-only. - State the SCC handoff correctly: when the google-scc connector creates the Asset first, that Asset keeps its existing Organization, and this connector only adds the folder relationship above it. - Document that a mapped Record's metadata never refreshes, so a folder rename or a project move in Google Cloud does not reach DefectDojo after the first sync. Same three corrections applied to the de/es/fr/ja translations.
…label needs roles/browser carries resourcemanager.folders.get and resourcemanager.organizations.get, but the page told readers a custom role with only the two list permissions works too. It does for the walk, and the top-level Asset then falls back to its resource id as its name because the connector cannot read the root's display name.
google-scc files a finding it cannot attribute to a project under a record for its configured parent, named after that resource. That is a different Asset from the organization or folder Asset the Google Cloud connector creates, so a customer running both sees one extra Asset for those findings. Keeping the display-name label on our root record was chosen over matching the bare resource name; this paragraph sets the expectation instead.
The Parent Resource field is now optional. Blank means every project the service account can read, as a flat list. With no organization there is no parent to grant the Browser role at, so it goes on each project instead.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documents the Google Cloud asset connector (sc-14524): what it imports, the service-account role it needs, the optional Parent Resource field, how it behaves alongside the Google Cloud SCC connector, and the two limits it ships with. Five languages, an index link in the upstream tool reference, and a bullet in the supported-tools list.
Runtime connector: DefectDojo-Inc/connectors#991.