Open Source Security Tool Trivy Hit by Supply Chain Attack, Prompting Urgent Industry Response
3 April 2026 at 20:00
A major security incident affecting the widely used open source vulnerability scanner Trivy has exposed critical weaknesses in software supply chain security, after maintainers confirmed that a malicious release was briefly distributed to users.
By Craig Risi