---
title: "Trivy Scanner v0.39.0"
description: "Release notes for the Trivy scanner adapter 0.39.0: Trivy is built from source, and adapter and Trivy binaries are published with each release."
date: 2026-10-02
lastmod: 2026-10-06
canonical: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.39.0/"
source: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.39.0/index.md"
agent_instructions: "This is the markdown representation of https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.39.0/index.md. Prefer this version over scraping the HTML. The site index is at https://container-registry.com/llms.txt."
---

> Agent-friendly representation of <https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.39.0/index.md>. Site index: <https://container-registry.com/llms.txt>.


# Trivy Scanner v0.39.0

*Release notes for the Trivy scanner adapter 0.39.0: Trivy is built from source, and adapter and Trivy binaries are published with each release.*

Trivy Scanner v0.39.0
=====================

Released 2026-07-03. [GitHub release](https://github.com/container-registry/harbor-scanner-trivy/releases/tag/v0.39.0)

## Features

- build Trivy from source and publish adapter and Trivy binaries ([#24](https://github.com/container-registry/harbor-scanner-trivy/issues/24))

## Container Image

Multi-arch image (`linux/amd64`, `linux/arm64`) signed with [cosign](https://github.com/sigstore/cosign).

| Image | Reference |
|-------|-----------|
| `harbor-scanner-trivy` | `8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.39.0` |

**Verify the image signature:**
```sh
cosign verify \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.39.0
```

**Verify the SBOM attestation:**
```sh
cosign verify-attestation \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  --type spdxjson \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:74a0c990e7bb007ba461f0860bd69b51d07a956ae96ae1aeac9afde89374ed1c
```

## Helm Chart

```sh
helm install harbor-scanner-trivy \
  oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
  --version 0.39.0
```

## Binaries

Static `linux/amd64` and `linux/arm64` binaries are attached to this release
(`checksums.txt` has the SHA256 sums):

| Asset | Contents |
|-------|----------|
| `scanner-trivy_linux-<arch>.tar.gz` | Harbor scanner adapter v0.39.0 |
| `trivy_linux-<arch>.tar.gz` | Trivy CLI v0.72.0, built from source |

