---
title: "Trivy Scanner v0.42.0"
description: "Release notes for the Trivy scanner adapter 0.42.0: operational metrics, scan failure classification, durable workers with Valkey and FIPS TLS settings."
date: 2026-10-02
lastmod: 2026-10-06
canonical: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.42.0/"
source: "https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.42.0/index.md"
agent_instructions: "This is the markdown representation of https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.42.0/index.md. Prefer this version over scraping the HTML. The site index is at https://container-registry.com/llms.txt."
---

> Agent-friendly representation of <https://container-registry.com/docs/scanner-trivy-releases/trivy-scanner-v0.42.0/index.md>. Site index: <https://container-registry.com/llms.txt>.


# Trivy Scanner v0.42.0

*Release notes for the Trivy scanner adapter 0.42.0: operational metrics, scan failure classification, durable workers with Valkey and FIPS TLS settings.*

Trivy Scanner v0.42.0
=====================

Released 2026-09-21. [GitHub release](https://github.com/container-registry/harbor-scanner-trivy/releases/tag/v0.42.0)

## Features

- **metrics:** classify scan failures, real readiness, queue self-recovery and engine defaults ([#110](https://github.com/container-registry/harbor-scanner-trivy/issues/110))
- **metrics:** Expose scanner operational telemetry ([#98](https://github.com/container-registry/harbor-scanner-trivy/issues/98))
- **perf:** Trivy scans with durable workers and dedicated Valkey ([#106](https://github.com/container-registry/harbor-scanner-trivy/issues/106))

## Upstream

- feat: restrict TLS cipher suites and curves for FIPS 140 compliance ([#109](https://github.com/container-registry/harbor-scanner-trivy/issues/109))

## Container Image

Multi-arch image (`linux/amd64`, `linux/arm64`) signed with [cosign](https://github.com/sigstore/cosign).

| Image | Reference |
|-------|-----------|
| `harbor-scanner-trivy` | `8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.42.0` |

**Verify the image signature:**
```sh
cosign verify \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy:v0.42.0
```

**Verify the SBOM attestation:**
```sh
cosign verify-attestation \
  --certificate-identity "https://github.com/container-registry/harbor-scanner-trivy/.github/workflows/publish-image.yml@refs/heads/main" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  --type spdxjson \
  8gears.container-registry.com/8gcr/harbor-scanner-trivy@sha256:75c8e5c5a1998af4b9a01292efc211c359a2590e389713580d09f89e96b4b3ba
```

## Helm Chart

The chart is released separately - see the [`chart-v*` releases](https://github.com/container-registry/harbor-scanner-trivy/releases?q=chart-v).
To deploy this adapter version with the latest chart:

```sh
helm install harbor-scanner-trivy \
  oci://8gears.container-registry.com/8gcr/charts/harbor-scanner-trivy \
  --set image.tag=v0.42.0
```

## Binaries

Static `linux/amd64` and `linux/arm64` binaries are attached to this release
(`checksums.txt` has the SHA256 sums):

| Asset | Contents |
|-------|----------|
| `scanner-trivy_linux-<arch>.tar.gz` | Harbor scanner adapter v0.42.0 |
| `trivy_linux-<arch>.tar.gz` | Trivy CLI v0.74.0, built from source |

