# Secure-by-default: Chainguard customers unaffected by the Trivy supply chain attack

DevFeed: [Secure-by-default: Chainguard customers unaffected by the Trivy supply chain attack](<https://devfeed.tech/articles/secure-by-default-chainguard-customers-unaffected-by-the-trivy-supply-chain-attack-12940.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-customers-unaffected-by-the-trivy-supply-chain-attack>)

Published: 2026-03-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [incident](<https://devfeed.tech/tags/incident.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Chainguard reports that its customers were unaffected by the March 19, 2026 supply chain attack involving malicious releases of the Trivy vulnerability scanner, trivy-action, and setup-trivy. The article explains how compromised credentials enabled the releases, why the incident threatened CI/CD pipeline secrets, and what organizations using the affected versions should do.

## Source excerpt

Chainguard customers are unaffected by the Trivy supply chain attack.