This page may contain stale information. Last updated: 2026-08-14

Overview

Trivy is a popular open-source vulnerability scanner. Its GitHub Actions compromise by teampcp was the upstream step that enabled theft of litellm PyPI publishing tokens in March 2026.

Recent Developments

  • 2026-03: Pipeline compromise → cascading supply-chain attacks (LiteLLM, KICS, Telnyx SDK)
  • Incomplete automation-token revocation gave attackers extended force-push window (CloudSEK)

Sources