Trivy Scanner v0.40.0
Released 2026-07-21. GitHub release
Highlights
Vulnerability scans can be served from an existing SBOM instead of pulling image layers, 6x to 35x faster. Opt-in.
When an image already carries an SBOM accessory generated by Harbor through this adapter, a vulnerability scan can run trivy sbom against that roughly 1 MB document instead of pulling, extracting and analyzing every layer (#38). Vulnerability matching still happens at scan time, so database updates apply in full. The biggest win is the scheduled “Scan All” after a database update: every artifact with an SBOM re-scans in well under a second with no layer traffic from the registry.
Enable it with SCANNER_TRIVY_USE_SBOM_ACCESSORY=true, or scanner.trivy.useSBOMAccessory: true in the Helm chart. Default is off.
Benchmark over 14 images (Trivy 0.72.0, linux/amd64, layers pulled from Docker Hub), selected rows:
| Image | Full image scan | SBOM scan | Speedup | Findings identical |
|---|---|---|---|---|
| node:22.14.0 | 8.4 s | 0.6 s | 14.0x | yes |
| tensorflow/tensorflow:2.18.0 | 12.4 s | 0.9 s | 13.8x | yes |
| homeassistant/home-assistant:2025.1.0 | 17.4 s | 0.5 s | 34.8x | yes |
| jenkins/jenkins:2.479.3-lts-jdk17 | 8.7 s | 0.3 s | 29.0x | yes |
| node:22.14.0-alpine | 2.4 s | 0.4 s | 6.0x | yes |
What to expect
- Applies to vulnerability scans only. SBOM generation and secret or misconfiguration scanning still read the image.
- Every failure falls back to a full image scan: no accessory found, referrers lookup error, or a failing
trivy sbomrun. - Requires SBOMs generated by Harbor with this adapter. Anyone with push rights can attach a foreign SBOM to an image, which is why the flag is off by default. A malformed SBOM fails the SBOM scan and falls back.
- An SBOM freezes the package inventory at generation time. If a newer Trivy learns new package types, regenerate the SBOM to pick them up.
Harbor now shows the exact Trivy build. The scanner version in Harbor’s Interrogation Service and in every scan report now reads 0.72.0 (8a328536), the Trivy release plus the source commit it was compiled from (#35). Since this fork builds Trivy from source with dependency overrides, the commit pins the provenance.
Container health check follows your server config. The Docker HEALTHCHECK added in v0.39.1 probed port 8080 unconditionally. It now reads the port from SCANNER_API_SERVER_ADDR and switches to HTTPS when SCANNER_API_SERVER_TLS_CERTIFICATE is set (#34). Known limitation: with mutual TLS the probe still fails because it has no client certificate to present.
Features
- build: include Trivy commit hash in scanner metadata (#35)
- Scan pre-existing SBOM accessory instead of image layers (#38)
Bug Fixes
- docker: derive HEALTHCHECK port and scheme from server config (#34)
Container Image
Multi-arch image (linux/amd64, linux/arm64) signed with cosign.
| Image | Reference |
|---|---|
harbor-scanner-trivy | 8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.0 |
Verify the image signature:
cosign verify \
--certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.0Verify the SBOM attestation:
cosign verify-attestation \
--certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
--type spdxjson \
8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:1d4c14935a17fbffd854dd72aa746d1d61a0dae6f4959760de8b18961c1a1c8cHelm Chart
helm install harbor-scanner-trivy \
oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
--version 0.40.0Binaries
Static linux/amd64 and linux/arm64 binaries are attached to this release
(checksums.txt has the SHA256 sums):
| Asset | Contents |
|---|---|
scanner-trivy_linux-<arch>.tar.gz | Harbor scanner adapter v0.40.0 |
trivy_linux-<arch>.tar.gz | Trivy CLI v0.72.0, built from source |