github.com/aquasecurity/trivy is vulnerable to Malicious Code
100
Critical Risk
Affected versions of Trivy were compromised in a supply chain attack where attackers published malicious releases and force-pushed tags to credential-stealing malware. The malicious payloads were capable of extracting secrets, SSH keys, cloud credentials, tokens, and other sensitive data from CI/CD environments and exfiltrating them to attacker-controlled infrastructure. Downgrading Trivy to version 0.69.3 is considered a safe mitigation.
You are affected if you are using a version that falls within the vulnerable range.
github.com/aquasecurity/trivy is vulnerable to Malicious Code in versions 0.69.4 - 0.69.6.
Upgrade the github.com/aquasecurity/trivy library to the patch version or downgrade to version 0.69.3.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant