For AI agents: a markdown representation of this page is available at https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.40.0/index.md. The site index is at https://container-registry.com/llms.txt.

Trivy Scanner v0.40.0

Released 2026-07-21. GitHub release

Highlights

Vulnerability scans can be served from an existing SBOM instead of pulling image layers, 6x to 35x faster. Opt-in.

When an image already carries an SBOM accessory generated by Harbor through this adapter, a vulnerability scan can run trivy sbom against that roughly 1 MB document instead of pulling, extracting and analyzing every layer (#38). Vulnerability matching still happens at scan time, so database updates apply in full. The biggest win is the scheduled “Scan All” after a database update: every artifact with an SBOM re-scans in well under a second with no layer traffic from the registry.

Enable it with SCANNER_TRIVY_USE_SBOM_ACCESSORY=true, or scanner.trivy.useSBOMAccessory: true in the Helm chart. Default is off.

Benchmark over 14 images (Trivy 0.72.0, linux/amd64, layers pulled from Docker Hub), selected rows:

ImageFull image scanSBOM scanSpeedupFindings identical
node:22.14.08.4 s0.6 s14.0xyes
tensorflow/tensorflow:2.18.012.4 s0.9 s13.8xyes
homeassistant/home-assistant:2025.1.017.4 s0.5 s34.8xyes
jenkins/jenkins:2.479.3-lts-jdk178.7 s0.3 s29.0xyes
node:22.14.0-alpine2.4 s0.4 s6.0xyes

What to expect

  • Applies to vulnerability scans only. SBOM generation and secret or misconfiguration scanning still read the image.
  • Every failure falls back to a full image scan: no accessory found, referrers lookup error, or a failing trivy sbom run.
  • Requires SBOMs generated by Harbor with this adapter. Anyone with push rights can attach a foreign SBOM to an image, which is why the flag is off by default. A malformed SBOM fails the SBOM scan and falls back.
  • An SBOM freezes the package inventory at generation time. If a newer Trivy learns new package types, regenerate the SBOM to pick them up.

Harbor now shows the exact Trivy build. The scanner version in Harbor’s Interrogation Service and in every scan report now reads 0.72.0 (8a328536), the Trivy release plus the source commit it was compiled from (#35). Since this fork builds Trivy from source with dependency overrides, the commit pins the provenance.

Container health check follows your server config. The Docker HEALTHCHECK added in v0.39.1 probed port 8080 unconditionally. It now reads the port from SCANNER_API_SERVER_ADDR and switches to HTTPS when SCANNER_API_SERVER_TLS_CERTIFICATE is set (#34). Known limitation: with mutual TLS the probe still fails because it has no client certificate to present.

Features

  • build: include Trivy commit hash in scanner metadata (#35)
  • Scan pre-existing SBOM accessory instead of image layers (#38)

Bug Fixes

  • docker: derive HEALTHCHECK port and scheme from server config (#34)

Container Image

Multi-arch image (linux/amd64, linux/arm64) signed with cosign.

ImageReference
harbor-scanner-trivy8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.0

Verify the image signature:

cosign verify \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.0

Verify the SBOM attestation:

cosign verify-attestation \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  --type spdxjson \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:1d4c14935a17fbffd854dd72aa746d1d61a0dae6f4959760de8b18961c1a1c8c

Helm Chart

helm install harbor-scanner-trivy \
  oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
  --version 0.40.0

Binaries

Static linux/amd64 and linux/arm64 binaries are attached to this release (checksums.txt has the SHA256 sums):

AssetContents
scanner-trivy_linux-<arch>.tar.gzHarbor scanner adapter v0.40.0
trivy_linux-<arch>.tar.gzTrivy CLI v0.72.0, built from source