Malware & Tooling · Supply Chain

Trivy GitHub Actions Compromise Exposes CI/CD Secrets

Attackers replaced published tags for aquasecurity/trivy-action and aquasecurity/setup-trivy with malicious versions that run inside GitHub Actions runners.

11 sources · Mar 25

Timeline

Sources

Part of the PlainSec briefing for 2026-03-26

Every edition of this story: Trivy GitHub Actions Compromise Exposes CI/CD Secrets

More from today