Skip to content

Confirm MSDO Trivy distribution is unaffected by supply chain attack #155

@ekbaramundi

Description

@ekbaramundi

On March 19, 2026, malicious Trivy versions 0.69.4–0.69.6 were published to Docker Hub and GitHub Releases (see aquasecurity/trivy#10425)

  • Is the SecDevTools NuGet feed confirmed unaffected?
  • Is the NuGet package built from verified source, or repackaged from GitHub Releases?
  • Does MSDO have integrity checks that would prevent a compromised upstream binary from entering the feed?
  • Environment: MSDO CLI 0.215.0, MicrosoftSecurityDevOps@1, Azure DevOps hosted agents (Windows)

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions