❌

Normal view

Open Source Security Tool Trivy Hit by Supply Chain Attack, Prompting Urgent Industry Response

3 April 2026 at 20:00

A major security incident affecting the widely used open source vulnerability scanner Trivy has exposed critical weaknesses in software supply chain security, after maintainers confirmed that a malicious release was briefly distributed to users.

By Craig Risi
❌