Skip to content

ci: update trivy-action to v0.35.0 after supply chain incident#186

Open
pranavjain97 wants to merge 3 commits intomasterfrom
fix/update-trivy-action
Open

ci: update trivy-action to v0.35.0 after supply chain incident#186
pranavjain97 wants to merge 3 commits intomasterfrom
fix/update-trivy-action

Conversation

@pranavjain97
Copy link
Copy Markdown
Contributor

The previous pin (v0.33.1) was affected by the March 2026 Trivy supply chain attack and its install script can no longer download the binary. Update to v0.35.0, the first clean release after remediation.

The previous pin (v0.33.1) was affected by the March 2026 Trivy supply
chain attack and its install script can no longer download the binary.
Update to v0.35.0, the first clean release after remediation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@pranavjain97 pranavjain97 requested a review from a team as a code owner March 31, 2026 20:16
@pranavjain97 pranavjain97 requested a review from mrdanish26 March 31, 2026 20:16
pranavjain97 and others added 2 commits March 31, 2026 16:28
Update overrides for transitive dependencies flagged by Trivy:
- axios: ^1.8.2 -> ^1.13.5 (CVE-2026-25639)
- tar: ^6.2.1 -> ^7.5.11 (6 CVEs)
- basic-ftp: ^5.2.0 (CVE-2026-27699, CRITICAL)
- flatted: ^3.4.0 (CVE-2026-32141)
- serialize-javascript: ^7.0.3 (GHSA-5c6j-r48x-rmvq)
- @isaacs/brace-expansion: ^5.0.1 (CVE-2026-25547)
- underscore: ^1.13.8 (CVE-2026-27601)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Override path-to-regexp to ^0.1.13 to fix ReDoS vulnerability.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant