Can you check whether the trivy breach affects users of drydock? #197
-
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
|
Thanks for flagging this @ovizii — this is a serious supply chain incident and it's a fair question. TL;DR: Drydock users are not affected by this breach.We've done a thorough audit and can confirm there is zero exposure across all three attack vectors. No CI runs occurred during the exposure window (March 19–20), and no compromised version was ever pulled or shipped. 1.
|
Beta Was this translation helpful? Give feedback.
Thanks for flagging this @ovizii — this is a serious supply chain incident and it's a fair question.
TL;DR: Drydock users are not affected by this breach.
We've done a thorough audit and can confirm there is zero exposure across all three attack vectors. No CI runs occurred during the exposure window (March 19–20), and no compromised version was ever pulled or shipped.
1.
aquasecurity/trivy-actionGitHub Action (primary attack vector)Not used. Drydock does not use
trivy-actionorsetup-trivyin any GitHub Actions workflow. The attacker force-pushed 76 of 77 release tags to malicious commits — but since we never reference these actions, our CI/CD pipelines were never exposed.2. Bundled T…