For AI agents: a markdown representation of this page is available at https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.39.1/index.md. The site index is at https://container-registry.com/llms.txt.

Trivy Scanner v0.39.1

Released 2026-07-12. GitHub release

Highlights

Scan reports take 5x to 17x less Redis memory.

Scan jobs and their reports are now gzip-compressed before they are written to Redis and decompressed transparently on read (#31). A bulk “Scan All” used to push the Redis instance the adapter shares with Harbor to 4.83 GiB and OOM-kill it (#28). At the measured ratios that same run stays in the 300 to 700 MB range.

Measurements:

ReportStoredUncompressedRatio
python:3.12 vulnerabilities322 KB2.27 MB7.2x
python:3.12 SBOM70 KB1.17 MB17.2x
alpine:3.19 vulnerabilities1.5 KB7.9 KB5.3x
alpine:3.19 SBOM2.9 KB27.5 KB9.4x

No configuration change, no key schema change, findings unchanged.

What you need to know when upgrading

  • Values written by the previous version stay readable, so a rolling upgrade works.
  • Compatibility is one-directional: an old replica cannot read the new compressed values. If several replicas share one Redis, upgrade them together. Values expire with the scan job TTL, so the window is short.
  • A scan job that expired before its report arrived now produces a clear error instead of a nil-pointer panic.

Docker Compose users get a working container health check. The image now ships lprobe and a Docker HEALTHCHECK on /probe/ready, and exposes ports 8080 and 8443 (#33). This makes the image a drop-in replacement for the trivy-adapter image built by harbor-next. The container user changed from fixed UID 10000 to a system user. Kubernetes deployments are unaffected: the Helm chart still enforces runAsUser: 10000 and probes over HTTP.

Bug Fixes

  • Add lprobe and align image user with harbor-next trivy-adapter (#33)
  • ci: bump Go to 1.26.5 to resolve GO-2026-5856 (#32)

Performance Improvements

  • add benchmark tests for trivy and scan packages (#12)
  • redis: gzip-compress stored scan job values (#31)

Container Image

Multi-arch image (linux/amd64, linux/arm64) signed with cosign.

ImageReference
harbor-scanner-trivy8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.39.1

Verify the image signature:

cosign verify \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.39.1

Verify the SBOM attestation:

cosign verify-attestation \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  --type spdxjson \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:29fac3e342b0dd4e1974868e01bb22b7f7a33cf52138ccb7de6705451ddd7c68

Helm Chart

helm install harbor-scanner-trivy \
  oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
  --version 0.39.1

Binaries

Static linux/amd64 and linux/arm64 binaries are attached to this release (checksums.txt has the SHA256 sums):

AssetContents
scanner-trivy_linux-<arch>.tar.gzHarbor scanner adapter v0.39.1
trivy_linux-<arch>.tar.gzTrivy CLI v0.72.0, built from source