---
title: "Trivy Scanner v0.40.1"
description: "Release notes for the Trivy scanner adapter 0.40.1: Scan All about 30% faster with far less Redis memory, Trivy built with CVE overrides, Go 1.26.6."
date: 2026-10-02
lastmod: 2026-10-06
canonical: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.40.1/"
source: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.40.1/index.md"
agent_instructions: "This is the markdown representation of https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.40.1/index.md. Prefer this version over scraping the HTML. The site index is at https://container-registry.com/llms.txt."
---

> Agent-friendly representation of <https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.40.1/index.md>. Site index: <https://container-registry.com/llms.txt>.


# Trivy Scanner v0.40.1

*Release notes for the Trivy scanner adapter 0.40.1: Scan All about 30% faster with far less Redis memory, Trivy built with CVE overrides, Go 1.26.6.*

Trivy Scanner v0.40.1
=====================

Released 2026-08-30. [GitHub release](https://github.com/container-registry/harbor-scanner-trivy/releases/tag/v0.40.1)

## Highlights

**"Scan All" runs about 30% faster and needs a fraction of the Redis memory.**

The scan report now lives in its own Redis key, separate from the small job status record ([#43](https://github.com/container-registry/harbor-scanner-trivy/pull/43)). Every status change (Queued, Pending, Finished) used to read, decompress, re-embed and rewrite the full multi-MB report. Now it touches only a few hundred bytes of metadata, and the report blob is written exactly once when the scan completes.

A full "Scan All" over 3,119 artifacts against the previous release:

| | Before | After | Change |
|---|---|---|---|
| "Scan All" wall time | 1h54m | 1h19m | 34 minutes faster (-30%) |
| Peak Redis memory during the run | 1,020 MB | 274 MB | -73% |

**The larger your scan reports (SBOMs, big images), the more this matters. Findings are unchanged: identical vulnerabilities and severities.**

**What you need to know when upgrading**

- Rolling upgrade is safe. Reports written by the previous version stay readable, survive status updates, and are replaced cleanly on rescan.
- Both keys share one TTL and are re-armed together, so a report can never outlive its job record.
- `SCANNER_STORE_REDIS_SCAN_JOB_TTL` is no longer hard-coded to `1h`. When unset it is derived from `SCANNER_TRIVY_TIMEOUT` as `2 x timeout + 3s` (10m3s with the default 5m timeout). Set it explicitly if you rely on reports staying in Redis longer. The Helm chart's `scanner.store.redisScanJobTTL` follows the same rule.
- `SCANNER_TRIVY_TIMEOUT` is now validated and must be between 0 and 24h.

Also in this release: the Trivy binary shipped in the image is built from source with 11 dependency overrides that close every fixable govulncheck finding in Trivy v0.72.0 ([#55](https://github.com/container-registry/harbor-scanner-trivy/pull/55)), and the adapter is built with Go 1.26.6 to pick up five stdlib fixes ([#50](https://github.com/container-registry/harbor-scanner-trivy/pull/50)).

## Bug Fixes

- **build:** apply CVE overrides when building Trivy from source ([#55](https://github.com/container-registry/harbor-scanner-trivy/issues/55))
- **deps:** bump Go to 1.26.6 for stdlib vulnerability fixes ([#50](https://github.com/container-registry/harbor-scanner-trivy/issues/50))

## Performance Improvements

- **redis:** split scan report into its own key ([#43](https://github.com/container-registry/harbor-scanner-trivy/issues/43))

## Documentation

- restructure README around fork rationale and measured performance ([#53](https://github.com/container-registry/harbor-scanner-trivy/issues/53))

## Container Image

Multi-arch image (`linux/amd64`, `linux/arm64`) signed with [cosign](https://github.com/sigstore/cosign).

| Image | Reference |
|-------|-----------|
| `harbor-scanner-trivy` | `8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.1` |

**Verify the image signature:**
```sh
cosign verify \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.40.1
```

**Verify the SBOM attestation:**
```sh
cosign verify-attestation \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  --type spdxjson \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:5fb5152868ab213ec662a6c7bb0c69ef7b777ce055246dd847940aae9013d455
```

## Helm Chart

```sh
helm install harbor-scanner-trivy \
  oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
  --version 0.40.1
```

## Binaries

Static `linux/amd64` and `linux/arm64` binaries are attached to this release
(`checksums.txt` has the SHA256 sums):

| Asset | Contents |
|-------|----------|
| `scanner-trivy_linux-<arch>.tar.gz` | Harbor scanner adapter v0.40.1 |
| `trivy_linux-<arch>.tar.gz` | Trivy CLI v0.72.0, built from source |

