Trivy under attack again: Widespread GitHub Actions tag compromise secrets
1–10 of 97 posts
Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#2Trivy ecosystem supply chain temporarily compromised - https://news.ycombinator.com/item?id=47450142 - March 2026 (35 comments)
Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#3So the first incident was on March 19th and the second incident is March 22nd —- evidently the attackers maintained persistence through maybe two separate credential rotation efforts.
Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#4Every month the security team wants me to give full code or cloud access to some new scanner they want to trial. They love the fancy dashboards and lengthy reports but if I allowed just 10% of what they wanted we would be pwned on the regular...
Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#5Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#6Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#7/s But I thought npm was the issue, and all of this couldn't happen anywhere else?!
Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#8Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#9Friendly reminder that just because someone is building security software it doesn't mean they are competent and won't cause more harm than good. Every month the security team wants me to give full code or cloud access to some new scanner they want to trial. They love the fancy dashboards and lengthy reports but if I allowed just 10% of what they wanted we would be pwned on the regular...