Skip to content

pin trivy-action to commit hash for release 0.35.0 to avoid compromised versions#1897

Merged
dandelany merged 1 commit into
developfrom
patch/pin-trivy-action-version
Mar 23, 2026
Merged

pin trivy-action to commit hash for release 0.35.0 to avoid compromised versions#1897
dandelany merged 1 commit into
developfrom
patch/pin-trivy-action-version

Conversation

@dandelany
Copy link
Copy Markdown
Collaborator

For details, see this security advisory:

GHSA-69fq-xp46-6x23

The trivy-action repository was temporarily compromised and malicious versions were pushed. The master version is now safe, but we were exposed to this during the compromise because we were not pinned to a specific version. Customers are not exposed to this vulnerability unless they fork our repository and try to run our CI actions.

We do not believe that any important secrets were exfiltrated, the main environment variables which it had access to were just for our temporary e2e testing environment and the canary testing environment. These will also be rotated.

More detailed report coming soon.

@dandelany dandelany requested a review from a team as a code owner March 23, 2026 22:28
@dandelany dandelany merged commit 13f0850 into develop Mar 23, 2026
5 checks passed
@dandelany dandelany deleted the patch/pin-trivy-action-version branch March 23, 2026 23:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants