Trivy Compromised in Supply Chain Attack

March 19 compromise of Aqua Security’s Trivy via GitHub Actions

Article includes list of hashes by Socket.dev

1 Like

Direct link to the GitHub discussion (not Security Advisory) about this.

We rotated secrets and tokens, but the process wasn’t atomic and attackers may have been privy to refreshed tokens. We are now taking a more restrictive approach and locking down all automated actions and any token in order to thoroughly eliminate the problem.

I’m having trouble seeing what they changed though.

Andre, do you mean to tell me you still haven’t contained this incident?