This page may contain stale information. Last updated: 2026-08-14
Overview
Trivy is a popular open-source vulnerability scanner. Its GitHub Actions compromise by teampcp was the upstream step that enabled theft of litellm PyPI publishing tokens in March 2026.
Recent Developments
- 2026-03: Pipeline compromise → cascading supply-chain attacks (LiteLLM, KICS, Telnyx SDK)
- Incomplete automation-token revocation gave attackers extended force-push window (CloudSEK)