software engineering
Software Engineering Exposes Trivy Scan Risks?
In 2024, a supply-chain attack compromised virtually all versions of the Trivy vulnerability scanner, proving that an unscanned container image cannot be trusted. The breach injected an infostealer via GitHub Actions, exposing secrets and giving attackers footholds in CI pipelines. Software Engineering Foundations for Vulnerability Hygiene When I first introduced