Skip to content

fix: bump Trivy to v0.69.2 following supply chain incident (#22896)#22911

Merged
chlins merged 1 commit intogoharbor:release-2.15.0from
wy65701436:release-2.15.0-cp-trivy
Mar 4, 2026
Merged

fix: bump Trivy to v0.69.2 following supply chain incident (#22896)#22911
chlins merged 1 commit intogoharbor:release-2.15.0from
wy65701436:release-2.15.0-cp-trivy

Conversation

@wy65701436
Copy link
Copy Markdown
Contributor

All GitHub Releases from v0.27.0 to v0.69.1 were permanently deleted on 2026-03-01 as part of a supply chain attack on aquasecurity/trivy. Update to v0.69.2, the emergency patch release published by Aqua Security.

Verified: curl -sI https://github.com/aquasecurity/trivy/releases/download/v0.69.2/trivy_0.69.2_Linux-64bit.tar.gz returns HTTP/2 302

Fixes #22895
Ref: https://github.com/aquasecurity/trivy/discussions/10265

Thank you for contributing to Harbor!

Comprehensive Summary of your change

Issue being fixed

Fixes #(issue)

Please indicate you've done the following:

  • Well Written Title and Summary of the PR
  • Label the PR as needed. "release-note/ignore-for-release, release-note/new-feature, release-note/update, release-note/enhancement, release-note/community, release-note/breaking-change, release-note/docs, release-note/infra, release-note/deprecation"
  • Accepted the DCO. Commits without the DCO will delay acceptance.
  • Made sure tests are passing and test coverage is added if needed.
  • Considered the docs impact and opened a new docs issue or PR with docs changes if needed in website repository.

Copy link
Copy Markdown
Member

@chlins chlins left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@codecov
Copy link
Copy Markdown

codecov Bot commented Mar 4, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (release-2.15.0@dfeeaf1). Learn more about missing BASE report.

Additional details and impacted files

Impacted file tree graph

@@                Coverage Diff                @@
##             release-2.15.0   #22911   +/-   ##
=================================================
  Coverage                  ?   66.01%           
=================================================
  Files                     ?     1074           
  Lines                     ?   116417           
  Branches                  ?     2937           
=================================================
  Hits                      ?    76858           
  Misses                    ?    35313           
  Partials                  ?     4246           
Flag Coverage Δ
unittests 66.01% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

…22896)

All GitHub Releases from v0.27.0 to v0.69.1 were permanently deleted
on 2026-03-01 as part of a supply chain attack on aquasecurity/trivy.
Update to v0.69.2, the emergency patch release published by Aqua Security.

Verified: curl -sI https://github.com/aquasecurity/trivy/releases/download/v0.69.2/trivy_0.69.2_Linux-64bit.tar.gz returns HTTP/2 302

Fixes goharbor#22895
Ref: https://github.com/aquasecurity/trivy/discussions/10265

Signed-off-by: Aloui-Ikram <ikram@container-registry.com>
Co-authored-by: Aloui-Ikram <ikram@container-registry.com>
Signed-off-by: wang yan <yan-yw.wang@broadcom.com>
@wy65701436 wy65701436 force-pushed the release-2.15.0-cp-trivy branch from a9e9bd6 to 9beb736 Compare March 4, 2026 04:29
@chlins chlins merged commit 06ce0f7 into goharbor:release-2.15.0 Mar 4, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants