Lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
steam_lover@sh.itjust.worksB to Docker@programming.dev · 6 days ago

Trivy supply chain compromise: What Docker Hub users should know

www.docker.com

external-link
message-square
0
link
fedilink
6
external-link

Trivy supply chain compromise: What Docker Hub users should know

www.docker.com

steam_lover@sh.itjust.worksB to Docker@programming.dev · 6 days ago
message-square
0
link
fedilink
Trivy supply chain compromise: What Docker Hub users should know | Docker
www.docker.com
external-link
On March 19, 2026, threat actors compromised Aqua Security's CI/CD pipeline and used stolen credentials to push backdoored versions of the aquasec/trivy vulnerability scanner to Docker Hub. A second wave of compromised images followed on March 22. The malicious images contained an infostealer targeting CI/CD secrets, cloud credentials, SSH keys, and Docker configurations. This post summarizes what happened, what Docker did in response, and what you should do if you use Trivy.
alert-triangle
You must log in or # to comment.

Docker@programming.dev

docker@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !docker@programming.dev
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 5 users / week
  • 10 users / month
  • 81 users / 6 months
  • 1 local subscriber
  • 1.42K subscribers
  • 50 Posts
  • 25 Comments
  • Modlog
  • mods:
  • Erlingur@programming.dev
  • ProgramPhoenix@programming.dev
  • Ategon@programming.dev
  • BE: 0.19.13
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org