For AI agents: a markdown representation of this page is available at https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.39.0/index.md. The site index is at https://container-registry.com/llms.txt.

Trivy Scanner v0.39.0

Released 2026-07-03. GitHub release

Features

  • build Trivy from source and publish adapter and Trivy binaries (#24)

Container Image

Multi-arch image (linux/amd64, linux/arm64) signed with cosign.

ImageReference
harbor-scanner-trivy8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.39.0

Verify the image signature:

cosign verify \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.39.0

Verify the SBOM attestation:

cosign verify-attestation \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  --type spdxjson \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:74a0c990e7bb007ba461f0860bd69b51d07a956ae96ae1aeac9afde89374ed1c

Helm Chart

helm install harbor-scanner-trivy \
  oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
  --version 0.39.0

Binaries

Static linux/amd64 and linux/arm64 binaries are attached to this release (checksums.txt has the SHA256 sums):

AssetContents
scanner-trivy_linux-<arch>.tar.gzHarbor scanner adapter v0.39.0
trivy_linux-<arch>.tar.gzTrivy CLI v0.72.0, built from source