Shipped · Security

What aquasecurity/trivy shipped

The public repository of Aqua Security · github.com/aquasecurity/trivy

Written by FoxPlug from public releases; not affiliated with Aqua Security. An automatic summary of the public release, pull request and commit data of github.com/aquasecurity/trivy. Aqua Security did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.

Get a weekly update like this for your product, free

Or Use it as a GitHub Action

Follow trivy's weekly shipped digest

Week of September 21, 2026

What shipped

Why it matters

Performance improvements in secret scanning and crypto handling reduce resource consumption on large scans, while fixes to VEX and SBOM parsing prevent crashes on malformed documents. Better support for modern cryptography and clearer security guidance for custom checks strengthen the project's reliability and safety.

Changelog entry

Example posts FoxPlug drafted from these changes. Not written or posted by the project.

Post for X

[1][2][6] This week: optimized secret scanning with Aho-Corasick, 14x memory reduction for repeated crypto material, ML-DSA support. [0][5] Fixed panics in VEX and SBOM parsing.

Post for LinkedIn

Trivy's latest release brings significant performance improvements and stability fixes. Secret scanning [1] now consolidates keyword searching into a single pass, while crypto scanning [2] reduces memory usage up to 14x for files with repeated certificates. We've added support for ML-DSA keys [6] from Go 1.27 and fixed crashes [0][5] when processing malformed VEX and SBOM documents. Additional improvements include better JSON line number handling [3], streamlined MANIFEST.MF parsing [4], and clearer security documentation [10] for custom checks.

Weeks with too little public activity are left out rather than filled in. Last updated 2026-09-30.

Is this your repo? Ask us to remove this page.