Trendora

Trivy

Assess

Tools

An open-source security scanner used for containers, dependencies, and infrastructure artifacts.

Why it's here

Placed in Assess: 1 article(s) of evidence from 1 source(s), led by security coverage, with 0 in the last 30 days. Confidence 24%. Low accumulated evidence, so it defaults conservatively pending more signal.

Evidence (1)

  • 8The New Stack·7/1/2026security
    Cordyceps flaw shows CI/CD is part of the attack surface

    Research from Novee Security describes the “Cordyceps” CI/CD weakness, which could let unauthenticated GitHub accounts hijack trusted workflows and compromise open-source supply chains. The report says it found hundreds of potentially exploitable repositories, reinforcing that CI/CD pipelines should be treated as security-critical production systems rather than mere configuration.