---
title: "Trivy Scanner v0.40.0"
description: "Release notes for the Trivy scanner adapter 0.40.0: opt-in vulnerability scans from an existing SBOM, 6x to 35x faster, and exact Trivy build in Harbor."
date: 2026-10-02
lastmod: 2026-10-06
canonical: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.40.0/"
source: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.40.0/index.md"
agent_instructions: "This is the markdown representation of https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.40.0/index.md. Prefer this version over scraping the HTML. The site index is at https://container-registry.com/llms.txt."
---

> Agent-friendly representation of <https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.40.0/index.md>. Site index: <https://container-registry.com/llms.txt>.


# Trivy Scanner v0.40.0

*Release notes for the Trivy scanner adapter 0.40.0: opt-in vulnerability scans from an existing SBOM, 6x to 35x faster, and exact Trivy build in Harbor.*

Trivy Scanner v0.40.0
=====================

Released 2026-07-21. [GitHub release](https://github.com/container-registry/harbor-scanner-trivy/releases/tag/v0.40.0)

## Highlights

**Vulnerability scans can be served from an existing SBOM instead of pulling image layers, 6x to 35x faster. Opt-in.**

When an image already carries an SBOM accessory generated by Harbor through this adapter, a vulnerability scan can run `trivy sbom` against that roughly 1 MB document instead of pulling, extracting and analyzing every layer ([#38](https://github.com/container-registry/harbor-scanner-trivy/pull/38)). Vulnerability matching still happens at scan time, so database updates apply in full. The biggest win is the scheduled "Scan All" after a database update: every artifact with an SBOM re-scans in well under a second with no layer traffic from the registry.

Enable it with `SCANNER_TRIVY_USE_SBOM_ACCESSORY=true`, or `scanner.trivy.useSBOMAccessory: true` in the Helm chart. Default is off.

Benchmark over 14 images (Trivy 0.72.0, linux/amd64, layers pulled from Docker Hub), selected rows:

| Image | Full image scan | SBOM scan | Speedup | Findings identical |
|---|---|---|---|---|
| node:22.14.0 | 8.4 s | 0.6 s | 14.0x | yes |
| tensorflow/tensorflow:2.18.0 | 12.4 s | 0.9 s | 13.8x | yes |
| homeassistant/home-assistant:2025.1.0 | 17.4 s | 0.5 s | 34.8x | yes |
| jenkins/jenkins:2.479.3-lts-jdk17 | 8.7 s | 0.3 s | 29.0x | yes |
| node:22.14.0-alpine | 2.4 s | 0.4 s | 6.0x | yes |

**What to expect**

- Applies to vulnerability scans only. SBOM generation and secret or misconfiguration scanning still read the image.
- Every failure falls back to a full image scan: no accessory found, referrers lookup error, or a failing `trivy sbom` run.
- Requires SBOMs generated by Harbor with this adapter. Anyone with push rights can attach a foreign SBOM to an image, which is why the flag is off by default. A malformed SBOM fails the SBOM scan and falls back.
- An SBOM freezes the package inventory at generation time. If a newer Trivy learns new package types, regenerate the SBOM to pick them up.

**Harbor now shows the exact Trivy build.** The scanner version in Harbor's Interrogation Service and in every scan report now reads `0.72.0 (8a328536)`, the Trivy release plus the source commit it was compiled from ([#35](https://github.com/container-registry/harbor-scanner-trivy/pull/35)). Since this fork builds Trivy from source with dependency overrides, the commit pins the provenance.

**Container health check follows your server config.** The Docker `HEALTHCHECK` added in v0.39.1 probed port 8080 unconditionally. It now reads the port from `SCANNER_API_SERVER_ADDR` and switches to HTTPS when `SCANNER_API_SERVER_TLS_CERTIFICATE` is set ([#34](https://github.com/container-registry/harbor-scanner-trivy/pull/34)). Known limitation: with mutual TLS the probe still fails because it has no client certificate to present.

## Features

- **build:** include Trivy commit hash in scanner metadata ([#35](https://github.com/container-registry/harbor-scanner-trivy/issues/35))
- Scan pre-existing SBOM accessory instead of image layers ([#38](https://github.com/container-registry/harbor-scanner-trivy/issues/38))

## Bug Fixes

- **docker:** derive HEALTHCHECK port and scheme from server config ([#34](https://github.com/container-registry/harbor-scanner-trivy/issues/34))

## Container Image

Multi-arch image (`linux/amd64`, `linux/arm64`) signed with [cosign](https://github.com/sigstore/cosign).

| Image | Reference |
|-------|-----------|
| `harbor-scanner-trivy` | `8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.0` |

**Verify the image signature:**
```sh
cosign verify \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.0
```

**Verify the SBOM attestation:**
```sh
cosign verify-attestation \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  --type spdxjson \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:1d4c14935a17fbffd854dd72aa746d1d61a0dae6f4959760de8b18961c1a1c8c
```

## Helm Chart

```sh
helm install harbor-scanner-trivy \
  oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
  --version 0.40.0
```

## Binaries

Static `linux/amd64` and `linux/arm64` binaries are attached to this release
(`checksums.txt` has the SHA256 sums):

| Asset | Contents |
|-------|----------|
| `scanner-trivy_linux-<arch>.tar.gz` | Harbor scanner adapter v0.40.0 |
| `trivy_linux-<arch>.tar.gz` | Trivy CLI v0.72.0, built from source |

