Skip to content

security: pin trivy binary to v0.69.3#153

Merged
mike-ainsel merged 1 commit intov4-betafrom
security/pin-trivy-version
Mar 20, 2026
Merged

security: pin trivy binary to v0.69.3#153
mike-ainsel merged 1 commit intov4-betafrom
security/pin-trivy-version

Conversation

@mike-ainsel
Copy link
Copy Markdown
Member

Summary

Pin trivy install script to download v0.69.3 (latest safe release)
instead of unpinned latest. v0.69.4 was compromised and removed.

See: https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise
@mike-ainsel mike-ainsel merged commit 1cb4dd2 into v4-beta Mar 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant