For AI agents: a markdown representation of this page is available at https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.40.1/index.md. The site index is at https://container-registry.com/llms.txt.

Trivy Scanner v0.40.1

Released 2026-08-30. GitHub release

Highlights

“Scan All” runs about 30% faster and needs a fraction of the Redis memory.

The scan report now lives in its own Redis key, separate from the small job status record (#43). Every status change (Queued, Pending, Finished) used to read, decompress, re-embed and rewrite the full multi-MB report. Now it touches only a few hundred bytes of metadata, and the report blob is written exactly once when the scan completes.

A full “Scan All” over 3,119 artifacts against the previous release:

BeforeAfterChange
“Scan All” wall time1h54m1h19m34 minutes faster (-30%)
Peak Redis memory during the run1,020 MB274 MB-73%

The larger your scan reports (SBOMs, big images), the more this matters. Findings are unchanged: identical vulnerabilities and severities.

What you need to know when upgrading

  • Rolling upgrade is safe. Reports written by the previous version stay readable, survive status updates, and are replaced cleanly on rescan.
  • Both keys share one TTL and are re-armed together, so a report can never outlive its job record.
  • SCANNER_STORE_REDIS_SCAN_JOB_TTL is no longer hard-coded to 1h. When unset it is derived from SCANNER_TRIVY_TIMEOUT as 2 x timeout + 3s (10m3s with the default 5m timeout). Set it explicitly if you rely on reports staying in Redis longer. The Helm chart’s scanner.store.redisScanJobTTL follows the same rule.
  • SCANNER_TRIVY_TIMEOUT is now validated and must be between 0 and 24h.

Also in this release: the Trivy binary shipped in the image is built from source with 11 dependency overrides that close every fixable govulncheck finding in Trivy v0.72.0 (#55), and the adapter is built with Go 1.26.6 to pick up five stdlib fixes (#50).

Bug Fixes

  • build: apply CVE overrides when building Trivy from source (#55)
  • deps: bump Go to 1.26.6 for stdlib vulnerability fixes (#50)

Performance Improvements

  • redis: split scan report into its own key (#43)

Documentation

  • restructure README around fork rationale and measured performance (#53)

Container Image

Multi-arch image (linux/amd64, linux/arm64) signed with cosign.

ImageReference
harbor-scanner-trivy8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.1

Verify the image signature:

cosign verify \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.1

Verify the SBOM attestation:

cosign verify-attestation \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  --type spdxjson \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:5fb5152868ab213ec662a6c7bb0c69ef7b777ce055246dd847940aae9013d455

Helm Chart

helm install harbor-scanner-trivy \
  oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
  --version 0.40.1

Binaries

Static linux/amd64 and linux/arm64 binaries are attached to this release (checksums.txt has the SHA256 sums):

AssetContents
scanner-trivy_linux-<arch>.tar.gzHarbor scanner adapter v0.40.1
trivy_linux-<arch>.tar.gzTrivy CLI v0.72.0, built from source