Trivy Security incident 2026-03-19

(github.com)

16 points | by l2dy 1 day ago

2 comments

  • tedivm 1 hour ago
    This is embarrassing. Trivy is a product I've recommended to a lot of people, and have even included it in my book on Terraform, but it's going to be very difficult recommending it going forward if they are going to continue to fail to protect their own artifacts and distribution chains.

    I don't expect my security tools to introduce back doors to my own build processes, and I especially don't expect to see it twice in three weeks.

  • macintux 1 hour ago
    Some discussion today.

    https://news.ycombinator.com/item?id=47471805

    There have been multiple posts on the topic, but none have gained traction.