veracarto
v0.1.8
Published
Ingests GCP and GitHub security findings, traces them to your running infrastructure, and surfaces the few that are actually exploitable.
Maintainers
Readme
Veracarto
Ingests GCP and GitHub security findings, traces them to your running infrastructure, and surfaces the few that are actually exploitable.
Setup (5 minutes)
1. Grant read-only access + enable APIs
bash <(curl -s https://api.veracarto.com/setup.sh) YOUR_PROJECT_ID2. Install
npm install -g veracarto3. Initialize
veracarto init4. Install the GitHub App
https://github.com/apps/veracarto/installations/new
What it does
- Ingests GCP SCC findings and GitHub Dependabot alerts
- Traces vulnerabilities to running Cloud Run services
- Surfaces only what's actually exploitable; filters the rest
- Sends gcloud fix commands to Slack; opens draft dependency PRs
- Read-only: never modifies your infrastructure
Permissions (all read-only)
roles/securitycenter.findingsViewerroles/cloudasset.viewerroles/logging.viewerroles/run.viewerroles/cloudbuild.builds.viewer
Commands
veracarto TUI dashboard
veracarto logs Agent activity feed
veracarto mapping Deployment pipeline map
veracarto status Non-interactive status
veracarto integrations Connection health