Trivy
AssessTools
An open-source security scanner used for containers, dependencies, and infrastructure artifacts.
Why it's here
Placed in Assess: 1 article(s) of evidence from 1 source(s), led by security coverage, with 0 in the last 30 days. Confidence 24%. Low accumulated evidence, so it defaults conservatively pending more signal.
Evidence (1)
- 8The New Stack·7/1/2026securityCordyceps flaw shows CI/CD is part of the attack surface
Research from Novee Security describes the “Cordyceps” CI/CD weakness, which could let unauthenticated GitHub accounts hijack trusted workflows and compromise open-source supply chains. The report says it found hundreds of potentially exploitable repositories, reinforcing that CI/CD pipelines should be treated as security-critical production systems rather than mere configuration.