---
title: "Trivy Scanner v0.41.0"
description: "Release notes for the Trivy scanner adapter 0.41.0: Helm chart moves to its own release line, x/crypto and x/text bumps, README fixes."
date: 2026-10-02
lastmod: 2026-10-06
canonical: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.41.0/"
source: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.41.0/index.md"
agent_instructions: "This is the markdown representation of https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.41.0/index.md. Prefer this version over scraping the HTML. The site index is at https://container-registry.com/llms.txt."
---

> Agent-friendly representation of <https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.41.0/index.md>. Site index: <https://container-registry.com/llms.txt>.


# Trivy Scanner v0.41.0

*Release notes for the Trivy scanner adapter 0.41.0: Helm chart moves to its own release line, x/crypto and x/text bumps, README fixes.*

Trivy Scanner v0.41.0
=====================

Released 2026-09-14. [GitHub release](https://github.com/container-registry/harbor-scanner-trivy/releases/tag/v0.41.0)

## Features

- **chart:** production-ready chart with an independent release line ([fa76805](https://github.com/container-registry/harbor-scanner-trivy/commit/fa768059b4f418419dddf8aaf20030ab08b7d215))

## Bug Fixes

- **chart:** let the chart release PR restamp the version in the generated README ([#72](https://github.com/container-registry/harbor-scanner-trivy/issues/72))
- **deps:** Bump x/crypto to v0.56.0 and x/text to v0.41.0 ([#108](https://github.com/container-registry/harbor-scanner-trivy/issues/108))

## Documentation

- add production Scan All numbers to the SBOM fast-path bullet ([#71](https://github.com/container-registry/harbor-scanner-trivy/issues/71))
- drop obsolete README content and fix config table facts ([#80](https://github.com/container-registry/harbor-scanner-trivy/issues/80))

## Container Image

Multi-arch image (`linux/amd64`, `linux/arm64`) signed with [cosign](https://github.com/sigstore/cosign).

| Image | Reference |
|-------|-----------|
| `harbor-scanner-trivy` | `8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.41.0` |

**Verify the image signature:**
```sh
cosign verify \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.41.0
```

**Verify the SBOM attestation:**
```sh
cosign verify-attestation \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  --type spdxjson \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:f84267a190e6f976950343031e9cd6081cbc266e1d7326e26dd8bfcfcf11a36b
```

## Helm Chart

The chart is released separately - see the [`chart-v*` releases](https://github.com/container-registry/harbor-scanner-trivy/releases?q=chart-v).
To deploy this adapter version with the latest chart:

```sh
helm install harbor-scanner-trivy \
  oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
  --set image.tag=v0.41.0
```

## Binaries

Static `linux/amd64` and `linux/arm64` binaries are attached to this release
(`checksums.txt` has the SHA256 sums):

| Asset | Contents |
|-------|----------|
| `scanner-trivy_linux-<arch>.tar.gz` | Harbor scanner adapter v0.41.0 |
| `trivy_linux-<arch>.tar.gz` | Trivy CLI v0.74.0, built from source |

