Trivy Scanner v0.39.1
Released 2026-07-12. GitHub release
Highlights
Scan reports take 5x to 17x less Redis memory.
Scan jobs and their reports are now gzip-compressed before they are written to Redis and decompressed transparently on read (#31). A bulk “Scan All” used to push the Redis instance the adapter shares with Harbor to 4.83 GiB and OOM-kill it (#28). At the measured ratios that same run stays in the 300 to 700 MB range.
Measurements:
| Report | Stored | Uncompressed | Ratio |
|---|---|---|---|
| python:3.12 vulnerabilities | 322 KB | 2.27 MB | 7.2x |
| python:3.12 SBOM | 70 KB | 1.17 MB | 17.2x |
| alpine:3.19 vulnerabilities | 1.5 KB | 7.9 KB | 5.3x |
| alpine:3.19 SBOM | 2.9 KB | 27.5 KB | 9.4x |
No configuration change, no key schema change, findings unchanged.
What you need to know when upgrading
- Values written by the previous version stay readable, so a rolling upgrade works.
- Compatibility is one-directional: an old replica cannot read the new compressed values. If several replicas share one Redis, upgrade them together. Values expire with the scan job TTL, so the window is short.
- A scan job that expired before its report arrived now produces a clear error instead of a nil-pointer panic.
Docker Compose users get a working container health check. The image now ships lprobe and a Docker HEALTHCHECK on /probe/ready, and exposes ports 8080 and 8443 (#33). This makes the image a drop-in replacement for the trivy-adapter image built by harbor-next. The container user changed from fixed UID 10000 to a system user. Kubernetes deployments are unaffected: the Helm chart still enforces runAsUser: 10000 and probes over HTTP.
Bug Fixes
- Add lprobe and align image user with harbor-next trivy-adapter (#33)
- ci: bump Go to 1.26.5 to resolve GO-2026-5856 (#32)
Performance Improvements
- add benchmark tests for trivy and scan packages (#12)
- redis: gzip-compress stored scan job values (#31)
Container Image
Multi-arch image (linux/amd64, linux/arm64) signed with cosign.
| Image | Reference |
|---|---|
harbor-scanner-trivy | 8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.39.1 |
Verify the image signature:
cosign verify \
--certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.39.1Verify the SBOM attestation:
cosign verify-attestation \
--certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
--type spdxjson \
8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:29fac3e342b0dd4e1974868e01bb22b7f7a33cf52138ccb7de6705451ddd7c68Helm Chart
helm install harbor-scanner-trivy \
oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
--version 0.39.1Binaries
Static linux/amd64 and linux/arm64 binaries are attached to this release
(checksums.txt has the SHA256 sums):
| Asset | Contents |
|---|---|
scanner-trivy_linux-<arch>.tar.gz | Harbor scanner adapter v0.39.1 |
trivy_linux-<arch>.tar.gz | Trivy CLI v0.72.0, built from source |