Title
Compromised aquasecurity/trivy-action detected in GitHub Actions workflows
Body
Compromised aquasecurity/trivy-action detected in GitHub Actions workflows
Our automated platform at StepSecurity has detected that this repository used a compromised version of aquasecurity/trivy-action in its GitHub Actions workflows during the recent Trivy incident.
What happened?
The aquasecurity/trivy-action GitHub Action was compromised, and a malicious version (v0.69.4) was published. Workflow runs in this repository executed a compromised SHA of this action, which may have exposed sensitive information such as secrets, environment variables, or build artifacts.
Compromised SHA detected
aquasecurity/trivy-action@91e7c2c36dcad14149d8e455b960af62a2ffb275
Affected workflow runs
References
Title
Compromised
aquasecurity/trivy-actiondetected in GitHub Actions workflowsBody
Compromised
aquasecurity/trivy-actiondetected in GitHub Actions workflowsOur automated platform at StepSecurity has detected that this repository used a compromised version of
aquasecurity/trivy-actionin its GitHub Actions workflows during the recent Trivy incident.What happened?
The
aquasecurity/trivy-actionGitHub Action was compromised, and a malicious version (v0.69.4) was published. Workflow runs in this repository executed a compromised SHA of this action, which may have exposed sensitive information such as secrets, environment variables, or build artifacts.Compromised SHA detected
aquasecurity/trivy-action@91e7c2c36dcad14149d8e455b960af62a2ffb275Affected workflow runs
References