Skip to content

[Trivy] TOOMANYREQUESTS DB error: database error: --skip-db-update cannot be specified on the first run #8807

Description

@daniel-mizsak

Hi,

Recently, I started often experiencing an older issue, where the trivy database is rate limited, resulting in a failing MegaLinter workflow run.

[trivy] [REPOSITORY_TRIVY_ERROR_DB_DOWNLOAD_FAILED] trivy could not download or refresh its vulnerability database from the configured registry.
Workarounds:
  - Retry the run; this is often transient.
  - Set `TRIVY_DB_REPOSITORY` to an alternative mirror (e.g. an internal registry or AWS ECR Public Gallery).
  - Pre-populate `~/.cache/trivy` in CI.
[trivy] [REPOSITORY_TRIVY_ERROR_DB_DOWNLOAD_FAILED] trivy could not download or refresh its vulnerability database from the configured registry.
Workarounds:
  - Retry the run; this is often transient.
  - Set `TRIVY_DB_REPOSITORY` to an alternative mirror (e.g. an internal registry or AWS ECR Public Gallery).
  - Pre-populate `~/.cache/trivy` in CI.
[trivy] [REPOSITORY_TRIVY_ERROR_DB_DOWNLOAD_FAILED] trivy could not download or refresh its vulnerability database from the configured registry.
Workarounds:
  - Retry the run; this is often transient.
  - Set `TRIVY_DB_REPOSITORY` to an alternative mirror (e.g. an internal registry or AWS ECR Public Gallery).
  - Pre-populate `~/.cache/trivy` in CI.
[trivy] [REPOSITORY_TRIVY_ERROR_DB_DOWNLOAD_FAILED] trivy could not download or refresh its vulnerability database from the configured registry.
Workarounds:
  - Retry the run; this is often transient.
  - Set `TRIVY_DB_REPOSITORY` to an alternative mirror (e.g. an internal registry or AWS ECR Public Gallery).
  - Pre-populate `~/.cache/trivy` in CI.
[trivy] [REPOSITORY_TRIVY_ERROR_DB_DOWNLOAD_FAILED] trivy could not download or refresh its vulnerability database from the configured registry.
Workarounds:
  - Retry the run; this is often transient.
  - Set `TRIVY_DB_REPOSITORY` to an alternative mirror (e.g. an internal registry or AWS ECR Public Gallery).
  - Pre-populate `~/.cache/trivy` in CI.
[Trivy] Hit TOOMANYREQUESTS 5 times: Run trivy with --skip-db-update and --skip-check-update
❌ Linted [REPOSITORY] files with [trivy]: Found 1 error(s) and 0 warning(s) - (20.22s) (expand for details)
  - Using [trivy v0.73.0] https://megalinter.io/10.0.0/descriptors/repository_trivy
  - MegaLinter key: [REPOSITORY_TRIVY]
  - Rules config: identified by [trivy]
  - CWD: [/github/workspace]
  - Commands:
    [trivy fs --scanners vuln,misconfig --exit-code 1 --skip-dirs **/.git --skip-dirs **/megalinter-reports .]
    [trivy fs --scanners vuln,misconfig --exit-code 1 --skip-dirs **/.git --skip-dirs **/megalinter-reports .]
    [trivy fs --scanners vuln,misconfig --exit-code 1 --skip-dirs **/.git --skip-dirs **/megalinter-reports .]
    [trivy fs --scanners vuln,misconfig --exit-code 1 --skip-dirs **/.git --skip-dirs **/megalinter-reports .]
    [trivy fs --scanners vuln,misconfig --exit-code 1 --skip-dirs **/.git --skip-dirs **/megalinter-reports .]
    [trivy fs --scanners vuln,misconfig --exit-code 1 --skip-dirs **/.git --skip-dirs **/megalinter-reports . --skip-db-update --skip-check-update]
  [Excluded directories] Forwarded EXCLUDED_DIRECTORIES to trivy through --skip-dirs (disable with REPOSITORY_TRIVY_FORWARD_EXCLUDED_DIRECTORIES: false)
  --Error detail:
  2026-08-26T07:50:43Z	ERROR	[vulndb] The first run cannot skip downloading DB
  2026-08-26T07:50:43Z	FATAL	Fatal error	run error: init error: DB error: database error: --skip-db-update cannot be specified on the first run

Related issues, discussion:

I am not sure about the best way to solve this but a few things that came to my mind:

Thank you for the help. :)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions