Trivy Scanner v0.40.1
Released 2026-08-30. GitHub release
Highlights
“Scan All” runs about 30% faster and needs a fraction of the Redis memory.
The scan report now lives in its own Redis key, separate from the small job status record (#43). Every status change (Queued, Pending, Finished) used to read, decompress, re-embed and rewrite the full multi-MB report. Now it touches only a few hundred bytes of metadata, and the report blob is written exactly once when the scan completes.
A full “Scan All” over 3,119 artifacts against the previous release:
| Before | After | Change | |
|---|---|---|---|
| “Scan All” wall time | 1h54m | 1h19m | 34 minutes faster (-30%) |
| Peak Redis memory during the run | 1,020 MB | 274 MB | -73% |
The larger your scan reports (SBOMs, big images), the more this matters. Findings are unchanged: identical vulnerabilities and severities.
What you need to know when upgrading
- Rolling upgrade is safe. Reports written by the previous version stay readable, survive status updates, and are replaced cleanly on rescan.
- Both keys share one TTL and are re-armed together, so a report can never outlive its job record.
SCANNER_STORE_REDIS_SCAN_JOB_TTLis no longer hard-coded to1h. When unset it is derived fromSCANNER_TRIVY_TIMEOUTas2 x timeout + 3s(10m3s with the default 5m timeout). Set it explicitly if you rely on reports staying in Redis longer. The Helm chart’sscanner.store.redisScanJobTTLfollows the same rule.SCANNER_TRIVY_TIMEOUTis now validated and must be between 0 and 24h.
Also in this release: the Trivy binary shipped in the image is built from source with 11 dependency overrides that close every fixable govulncheck finding in Trivy v0.72.0 (#55), and the adapter is built with Go 1.26.6 to pick up five stdlib fixes (#50).
Bug Fixes
- build: apply CVE overrides when building Trivy from source (#55)
- deps: bump Go to 1.26.6 for stdlib vulnerability fixes (#50)
Performance Improvements
- redis: split scan report into its own key (#43)
Documentation
- restructure README around fork rationale and measured performance (#53)
Container Image
Multi-arch image (linux/amd64, linux/arm64) signed with cosign.
| Image | Reference |
|---|---|
harbor-scanner-trivy | 8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.1 |
Verify the image signature:
cosign verify \
--certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.1Verify the SBOM attestation:
cosign verify-attestation \
--certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
--type spdxjson \
8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:5fb5152868ab213ec662a6c7bb0c69ef7b777ce055246dd847940aae9013d455Helm Chart
helm install harbor-scanner-trivy \
oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
--version 0.40.1Binaries
Static linux/amd64 and linux/arm64 binaries are attached to this release
(checksums.txt has the SHA256 sums):
| Asset | Contents |
|---|---|
scanner-trivy_linux-<arch>.tar.gz | Harbor scanner adapter v0.40.1 |
trivy_linux-<arch>.tar.gz | Trivy CLI v0.72.0, built from source |