Skip to content

chore(trivy): Update trivy to 0.35.0 due to vuln#176

Merged
cloudnull merged 1 commit into
rackerlabs:mainfrom
LukeRepko:trivy
Mar 23, 2026
Merged

chore(trivy): Update trivy to 0.35.0 due to vuln#176
cloudnull merged 1 commit into
rackerlabs:mainfrom
LukeRepko:trivy

Conversation

@LukeRepko

Copy link
Copy Markdown
Contributor

There was a vulnerability in most/all previous versions of trivy. 0.35.0 is the only clean tag available at this time.

Ref: https://www.crowdstrike.com/en-us/blog/from-scanner-to-stealer-inside-the-trivy-action-supply-chain-compromise

There was a vulnerability in most/all previous versions of trivy. 0.35.0
is the only clean tag available at this time.

Ref: https://www.crowdstrike.com/en-us/blog/from-scanner-to-stealer-inside-the-trivy-action-supply-chain-compromise
@LukeRepko LukeRepko requested a review from rackerchris March 23, 2026 20:57

@rackerchris rackerchris left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM +1

@cloudnull cloudnull merged commit 57ad86f into rackerlabs:main Mar 23, 2026
94 of 100 checks passed
@LukeRepko LukeRepko deleted the trivy branch March 24, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants