Skip to content

Comment on Trivy ecosystem supply chain temporarily compromised

Comments

This attack seems predicated on a prior security incident (https://socket.dev/blog/unauthorized-ai-agent-execution-code...) at Trivy where they failed to successfully remediate and contain the damage. I think at this time, Trivy should’ve undertaken a full reassessment of risks and clearly isolated credentials and reduced risk systemically. This did not happen, and the second compromise occurred.

They did a lot of what you describe, although perhaps not well enough.

It seems not enough again, as their Docker images have now been compromised (as of March 22nd, 2026): https://github.com/aquasecurity/trivy/security/advisories/GH...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.