Skip to content
>_ITDITDWeb Security Platform

Security Guides

The vulnerability scanner became the way in — what CI users should do after the Trivy supply-chain compromise

On March 19–20, 2026, a malicious Trivy v0.69.4 was released and the trivy-action and setup-trivy tags were rewritten, targeting CI secrets. Based on Aqua Security's disclosure: affected versions and time windows, secret rotation, SHA pinning and least-privilege CI tokens.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 15 min read

For: anyone running Trivy (the container image and dependency vulnerability scanner), aquasecurity/trivy-action or aquasecurity/setup-trivy in CI such as GitHub Actions, and anyone using Trivy binaries or container images on a workstation or server. This article is based on Aqua Security's official disclosure and Trivy's security advisory and does not cover attack techniques or indicator-of-compromise (IoC) values.

What CI users should do today

1

Check whether any Trivy-related workflow ran in the affected windows

Aqua asks users to review workflow run logs from March 19–20, 2026. The windows in the advisory (UTC) are: trivy-action, about 17:43 on March 19 to about 05:40 on March 20; setup-trivy, about 17:43 to about 21:44 on March 19; Trivy v0.69.4, 18:22 to about 21:42 on March 19; Docker Hub images v0.69.5 and v0.69.6, 15:43 on March 22 to about 01:40 on March 23. If your organization has many workflows, search for those referencing aquasecurity/trivy-action and aquasecurity/setup-trivy and filter their run history by these windows.

2

Decide by how you referenced it, not only by version

In the advisory, what matters is how you referenced the component.
trivy-action — affected: any tag other than 0.35.0 (0.0.1–0.34.2); version: latest set explicitly during the window; a SHA pin to a commit from before April 9, 2025. Not affected: the 0.35.0 tag; SHA pins to safe commits after April 9, 2025.
setup-trivy — affected: any use without a SHA pin. Not affected: SHA pins to safe commits.
Trivy itself — affected: v0.69.4 (including latest during the window; GitHub, deb, rpm, get.trivy.dev, GHCR, ECR Public, Docker Hub) and Docker Hub v0.69.5 and v0.69.6. Not affected: v0.69.3 and earlier; images referenced by digest; builds from source; the official Homebrew formula.

3

If affected, rotate every secret the job could read

Aqua says that if there is any possibility a compromised version ran, all secrets accessible to the affected pipelines must be treated as exposed: cloud credentials (AWS, GCP, Azure), Git credentials, container registry credentials, SSH keys, Kubernetes tokens, and environment variables and other automation secrets. It asks that npm publish tokens be treated as actively compromised, saying stolen tokens are being used to spread malware across npm. For self-hosted runners, Aqua also lists database credentials, TLS private keys and VPN configurations stored on the runner.

4

Rotate by stopping everything first, then reissuing together

This step comes from Trivy's own root cause. According to Aqua, the March 1 rotation was not done all at once, and during a rotation that took several days, the attacker may have used a still-valid token to take even the newly issued secrets. Once you have listed the secrets in scope, invalidate the old keys together first, then issue new ones. Rotating one key at a time leaves room for a still-valid old key to read the new ones. Plan for a short outage as the price.

5

Check your GitHub organization and any machine that ran Trivy, using the advisory's checklist

Aqua lists, as items to check, a repository created in your GitHub organization if a fallback exfiltration path was used, and files left on a machine where v0.69.4 ran outside CI, such as a developer workstation. If you may be affected, follow the checklists in Aqua's disclosure and the advisory linked below (this article does not reproduce the indicator values).

6

Move to the known-safe versions

Aqua lists the safe versions as Trivy v0.69.2 and v0.69.3, trivy-action v0.35.0, and setup-trivy v0.2.6. According to the advisory, the old trivy-action tags (0.0.1–0.34.2) were deleted and cannot be re-created under the same names, so they were republished with a v prefix (for example v0.34.0), pointing to the original legitimate commits (a few have not been restored). If you still reference an older version, you need to update the reference.

What to review in your CI configuration

The basic rule of pinning actions by commit SHA is covered in the TanStack, Nx Console and GitHub chain. Here we focus on what the Trivy incident adds.

1

Check what a SHA-pinned action calls by tag inside

According to the advisory, trivy-action switched its internal component references to SHA pins in a pull request merged on April 9, 2025. People who pinned trivy-action to an earlier commit had a safe trivy-action that called a malicious setup-trivy by tag. If you use actions built from other actions (composite actions), open the action.yml at the commit you pinned and check whether the uses: lines inside are pinned by SHA. If not, move to a newer commit or call the inner components directly from your own workflow, pinned by SHA.

2

Enforce SHA pinning as policy rather than a request

In August 2025, GitHub added an option to the allowed-actions policy that requires actions to be pinned to a full commit SHA. It can be set at the enterprise, organization or repository level, and workflows that use an unpinned action fail. The same policy can block specific actions or versions, which also gives you a way to shut off an affected version across the whole organization during an incident like this.

3

Do not rely on the ‘Immutable’ badge alone

According to the advisory, Trivy v0.69.3 and trivy-action 0.35.0 escaped because GitHub's immutable releases were enabled before they were published. Aqua, however, says the "Immutable" badge also appeared next to rewritten tags, and that pinning to a full commit SHA, not the badge, is the reliable protection. The badge describes a release as of when it was published.

4

Pin binaries by version and verify signatures; reference images by digest

In the advisory, images referenced by digest (@sha256:…) were not affected. Pulling by latest or a version tag alone would have picked up the malicious build during the window. Trivy's advisory also shows how to verify binaries and images with Sigstore signatures and signing timestamps. For tools your CI downloads, state the version and, where possible, pin by digest or checksum.

5

Run the scanner in a job that holds no deployment secrets

According to Aqua, the malicious code ran before the legitimate scan, and the scan output looked normal, which made it hard to notice. A scan normally needs no write access to your cloud or registry. Run scanning in a separate job that receives no deployment secrets, with permissions: set to read-only. According to Aqua, the fallback exfiltration path worked only when a personal access token (PAT) was passed to the workflow and failed with the default GITHUB_TOKEN. Check that you are not handing a personal token to your scanning step.

What happened (from Aqua Security's disclosure)

Everything below is as stated in Aqua Security's disclosure (initial post of March 22 and updates through April 1) and Trivy's security advisory. Times are UTC.

  1. Late February 2026

    A misconfiguration in Trivy's GitHub Actions environment is exploited and a privileged access token is extracted.
  2. March 1

    The Trivy team discloses that incident and rotates credentials. According to Aqua, the rotation was not done all at once, and the attacker kept access through still-valid credentials.
  3. March 19, about 17:43

    76 of 77 trivy-action tags and all 7 setup-trivy tags are repointed to malicious commits. At the same time, a compromised service account triggers the release automation and publishes a malicious Trivy v0.69.4 (artifacts available from 18:22).
  4. March 19, about 20:38

    The Trivy team identifies and contains the attack and removes malicious artifacts from distribution channels.
  5. March 20

    Safe versions, user guidance and indicators of compromise are published.
  6. March 21

    Security advisory GHSA-69fq-xp46-6x23 (CVE-2026-33634) is published.
  7. March 22

    Malicious images v0.69.5 and v0.69.6 are pushed to Docker Hub (using separately compromised Docker Hub credentials). The same day, internal Aqua repositories are made public on GitHub without authorization. Aqua says the attacker had re-established access after the initial containment.
  8. March 23

    Aqua brings an outside incident response firm into the investigation. A parallel compromise of the GitHub Action for KICS, another Aqua scanner, is identified.
  9. April 1

    Aqua says the investigation is nearly final and there is still no indication that its commercial products were affected.
76 / 77
trivy-action tags repointed (only 0.35.0 was safe)
7 / 7
setup-trivy tags repointed
~12 hours
How long trivy-action tags were rewritten (advisory)
No indication
of impact on commercial products, incl. Trivy in the Aqua Platform (Aqua)
What Aqua Security disclosed
Affected
Trivy v0.69.4 (binaries, deb/rpm, container images), Docker Hub v0.69.5 and v0.69.6, every trivy-action tag except 0.35.0, every setup-trivy tag
What the code did
Collected cloud, SSH, Kubernetes, Docker, Git and database credentials and .env files from CI runners and machines, encrypted them and sent them out. It ran before the legitimate scan, so results looked normal
Cause
A privileged token extracted in late February through a GitHub Actions misconfiguration; because the March 1 rotation was not atomic, access was retained
Aqua's response
Deleted malicious artifacts from all channels; deleted or repointed the rewritten tags to verified commits; locked down all automation, service accounts and tokens in the open-source organization; reduced reliance on long-lived credentials; introduced immutable release verification and provenance attestations
Not affected
Commercial products including Trivy in the Aqua Platform (built on infrastructure separate from GitHub, sharing no secrets or signing systems)

Reading note: no victim count has been published

Aqua says that because Trivy is open source, it has no comprehensive record of its users and no way to notify every user directly. No count of affected organizations has been published, and this site does not print estimates. Aqua's disclosure also names the attacker and the outside firms that helped with analysis; by this site's policy we name only the organization that disclosed the incident. Decide by whether your workflow ran in the window with an affected reference, not by headline numbers.

Where it could have been stopped

1. Late Feb – March 1

Token extracted; rotation takes days

↓

Lesson (in your org)

Stop everything, then reissue together

2. March 19: tags rewritten

Same tag names now point to malicious commits

↓

Stop point

SHA pins enforced by policy, inner parts pinned too

3. Malicious v0.69.4 and latest

Shipped on every official channel

↓

Stop point

Explicit versions, digests, signature checks

4. Your CI job

Secrets collected before the scan runs

↓

Limit the damage

No secrets or personal tokens in the scan job

The path as reconstructed from Aqua Security's disclosure and the advisory. The right side of each step shows the setting on the user side that could stop or reduce the damage.

References that were affected (per the advisory)

  • Tag references such as trivy-action@0.34.2 (anything but 0.35.0)
  • Explicit version: latest (during the binary window)
  • SHA pins to commits before April 9, 2025 (inner setup-trivy called by tag)
  • Any setup-trivy reference without a SHA pin
  • Image tags such as latest or 0.69.4

References that were not affected

  • trivy-action@0.35.0 (immutable releases enabled before it was published)
  • SHA pins to safe commits after April 9, 2025
  • setup-trivy SHA-pinned to a safe commit
  • Images referenced by digest
  • Trivy v0.69.3 and earlier, builds from source, the official Homebrew formula

This site's view: rotation is containment, not maintenance

Key rotation is usually done "one key at a time, least critical first, without downtime." Avoiding downtime is a real benefit, but the Trivy incident shows that this approach does not contain anything while an attacker is still inside. According to Aqua, during a rotation that stretched over several days, a still-valid token may have been used to take even the newly issued secrets, and that led to the malicious release three weeks later.

When a compromise is suspected, rotate in this order: (1) list every key and where it could be read from, (2) invalidate the old keys together, (3) only then issue new ones, (4) confirm the old keys really fail. Plan for a short outage. The routine method — running old and new side by side — assumes nothing has leaked.

One more point. Because a vulnerability scanner is a "defensive" tool, it tends to run in more places, with broader permissions, than almost anything else in CI. The more defensive the tool, the farther from your secrets it should run.

Sources (public record)

The facts in this article come from the public sources below. Attack techniques, IoC values and information identifying the attacker are not covered.

  • Aqua Security, "Trivy Supply Chain Attack: What You Need to Know" (initial post March 22, 2026, updated April 1) — aquasec.com
  • Trivy security advisory, "Trivy ecosystem supply chain temporarily compromised," GHSA-69fq-xp46-6x23 (CVE-2026-33634; published March 21, updated March 30) — github.com
  • Trivy, "Trivy Security incident 2026-03-19" (GitHub Discussions, status updates from the Trivy team) — github.com
  • GitHub Changelog, "GitHub Actions policy now supports blocking and SHA pinning actions" (August 15, 2025) — github.blog
  • GitHub Docs, "Secure use reference" (using third-party actions) — docs.github.com

Update history

2026-09-30: First version, based on Aqua Security's disclosure (April 1 update) and Trivy's security advisory (March 30 revision).

FAQ

QWhich Trivy versions were affected?
A

According to Trivy's security advisory GHSA-69fq-xp46-6x23 (CVE-2026-33634), the affected artifacts were Trivy v0.69.4 (binaries distributed via GitHub, deb, rpm and get.trivy.dev, and container images on GHCR, ECR Public and Docker Hub; the latest tag also pointed to it during the exposure window) and container images v0.69.5 and v0.69.6 published to Docker Hub. v0.69.3 and earlier, images referenced by digest, binaries built from source, and the official Homebrew formula were not affected.

QI use trivy-action. Am I affected?
A

According to the advisory, you are affected if you referenced any tag other than 0.35.0 (0.0.1 through 0.34.2), explicitly set version: latest during the binary exposure window, or pinned by SHA to a commit from before April 9, 2025. The 0.35.0 tag and SHA pins to safe commits after April 9, 2025 were not affected. The tags were rewritten from about 17:43 UTC on March 19 to about 05:40 UTC on March 20, 2026.

QI use setup-trivy. Am I affected?
A

According to the advisory, any use without SHA pinning is affected. All seven tags (v0.2.0 through v0.2.6) were repointed to malicious commits between about 17:43 and 21:44 UTC on March 19. SHA pins to safe commits were not affected, and v0.2.6 was re-created with safe content.

QWhat should I do if I was affected?
A

Aqua says that if there is any possibility a compromised version ran in your environment, every secret the affected pipelines could reach must be treated as exposed and rotated immediately: cloud credentials (AWS, GCP, Azure), Git credentials, container registry credentials, SSH keys, Kubernetes tokens, environment variables and other automation secrets. It says npm publish tokens should be treated as actively compromised.

QWhat was the cause?
A

According to Aqua, in late February 2026 attackers exploited a misconfiguration in Trivy's GitHub Actions environment and extracted a privileged access token. The incident was disclosed and credentials were rotated on March 1, but the rotation was not atomic (it took a few days), and the attacker may have used a still-valid token to obtain the newly rotated secrets. Aqua says this allowed the March 19 malicious release.

QWere Aqua Security's commercial products affected?
A

Aqua says there is no indication that its commercial products were affected, including Trivy as delivered within the Aqua Platform. It explains that the commercial platform is built and operated separately from GitHub, shares no repositories, CI/CD infrastructure, secrets or signing systems, and takes in open-source releases only after a gated security review. That statement does not apply to direct use of open-source Trivy.