Where
-Infinity
0

On Sat, 21 Mar 2026 at 20:40, Alan Coopersmith <alan.coopersmith () oracle com> wrote: https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise reports that a compromised credential with write access to the repository was used to modify 75 out of 76 version tags in the aquasecurity/trivy-action repository, the official GitHub Action for running Trivy vulnerability scans in CI/CD pipelines. Of note, this attack is still on-going and the extent of Trivy's compromise seems to be growing. After the above was announced, further malicious actions were taken by the third party targeting them. https://socket.dev/blog/trivy-docker-images-compromised details how additional compromised Trivy artifacts (image tags 0.69.5 and 0.69.6) were published to Docker Hub on March 22 without corresponding GitHub releases or tags.

Trivy published a GitHub Security Advisory and has since updated it with the new Docker Hub compromise information: https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23

Cheers, Jeremy

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203