Skip to content

Confirm MSDO Trivy distribution is unaffected by supply chain attack #155

@ekbaramundi

Description

@ekbaramundi

On March 19, 2026, malicious Trivy versions 0.69.4–0.69.6 were published to Docker Hub and GitHub Releases (see aquasecurity/trivy#10425)

  • Is the SecDevTools NuGet feed confirmed unaffected?
  • Is the NuGet package built from verified source, or repackaged from GitHub Releases?
  • Does MSDO have integrity checks that would prevent a compromised upstream binary from entering the feed?
  • Environment: MSDO CLI 0.215.0, MicrosoftSecurityDevOps@1, Azure DevOps hosted agents (Windows)

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions