---
title: "Trivy Scanner v0.39.1"
description: "Release notes for the Trivy scanner adapter 0.39.1: gzip-compressed scan jobs and reports cut Redis memory 5x to 17x, plus a container health check."
date: 2026-10-02
lastmod: 2026-10-06
canonical: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.39.1/"
source: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.39.1/index.md"
agent_instructions: "This is the markdown representation of https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.39.1/index.md. Prefer this version over scraping the HTML. The site index is at https://container-registry.com/llms.txt."
---

> Agent-friendly representation of <https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.39.1/index.md>. Site index: <https://container-registry.com/llms.txt>.


# Trivy Scanner v0.39.1

*Release notes for the Trivy scanner adapter 0.39.1: gzip-compressed scan jobs and reports cut Redis memory 5x to 17x, plus a container health check.*

Trivy Scanner v0.39.1
=====================

Released 2026-07-12. [GitHub release](https://github.com/container-registry/harbor-scanner-trivy/releases/tag/v0.39.1)

## Highlights

**Scan reports take 5x to 17x less Redis memory.**

Scan jobs and their reports are now gzip-compressed before they are written to Redis and decompressed transparently on read ([#31](https://github.com/container-registry/harbor-scanner-trivy/pull/31)). A bulk "Scan All" used to push the Redis instance the adapter shares with Harbor to 4.83 GiB and OOM-kill it ([#28](https://github.com/container-registry/harbor-scanner-trivy/issues/28)). At the measured ratios that same run stays in the 300 to 700 MB range.

Measurements:

| Report | Stored | Uncompressed | Ratio |
|---|---|---|---|
| python:3.12 vulnerabilities | 322 KB | 2.27 MB | 7.2x |
| python:3.12 SBOM | 70 KB | 1.17 MB | 17.2x |
| alpine:3.19 vulnerabilities | 1.5 KB | 7.9 KB | 5.3x |
| alpine:3.19 SBOM | 2.9 KB | 27.5 KB | 9.4x |

No configuration change, no key schema change, findings unchanged.

**What you need to know when upgrading**

- Values written by the previous version stay readable, so a rolling upgrade works.
- Compatibility is one-directional: an old replica cannot read the new compressed values. If several replicas share one Redis, upgrade them together. Values expire with the scan job TTL, so the window is short.
- A scan job that expired before its report arrived now produces a clear error instead of a nil-pointer panic.

**Docker Compose users get a working container health check.** The image now ships `lprobe` and a Docker `HEALTHCHECK` on `/probe/ready`, and exposes ports 8080 and 8443 ([#33](https://github.com/container-registry/harbor-scanner-trivy/pull/33)). This makes the image a drop-in replacement for the `trivy-adapter` image built by harbor-next. The container user changed from fixed UID 10000 to a system user. Kubernetes deployments are unaffected: the Helm chart still enforces `runAsUser: 10000` and probes over HTTP.

## Bug Fixes

- Add lprobe and align image user with harbor-next trivy-adapter ([#33](https://github.com/container-registry/harbor-scanner-trivy/issues/33))
- **ci:** bump Go to 1.26.5 to resolve GO-2026-5856 ([#32](https://github.com/container-registry/harbor-scanner-trivy/issues/32))

## Performance Improvements

- add benchmark tests for trivy and scan packages ([#12](https://github.com/container-registry/harbor-scanner-trivy/issues/12))
- **redis:** gzip-compress stored scan job values ([#31](https://github.com/container-registry/harbor-scanner-trivy/issues/31))

## Container Image

Multi-arch image (`linux/amd64`, `linux/arm64`) signed with [cosign](https://github.com/sigstore/cosign).

| Image | Reference |
|-------|-----------|
| `harbor-scanner-trivy` | `8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.39.1` |

**Verify the image signature:**
```sh
cosign verify \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.39.1
```

**Verify the SBOM attestation:**
```sh
cosign verify-attestation \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  --type spdxjson \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:29fac3e342b0dd4e1974868e01bb22b7f7a33cf52138ccb7de6705451ddd7c68
```

## Helm Chart

```sh
helm install harbor-scanner-trivy \
  oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
  --version 0.39.1
```

## Binaries

Static `linux/amd64` and `linux/arm64` binaries are attached to this release
(`checksums.txt` has the SHA256 sums):

| Asset | Contents |
|-------|----------|
| `scanner-trivy_linux-<arch>.tar.gz` | Harbor scanner adapter v0.39.1 |
| `trivy_linux-<arch>.tar.gz` | Trivy CLI v0.72.0, built from source |

