All corrections
X March 20, 2026 at 08:25 PM

x.com/feross/status/2034845411459191173?s=20

1 correction found

1
Claim
That's @0.0.1 all the way through @0.34.2.
Correction

The top documented affected trivy-action tag was 0.34.0, not 0.34.2. Aqua’s own maintainer later described the restored compromised range as v0.0.1 through v0.34.0, and GitHub’s API has no 0.34.2/v0.34.2 tag or release for this repo.

Full reasoning

This appears to overstate the highest affected trivy-action version.

Aqua maintainer DmitriyLewen wrote in the official aquasecurity/trivy-action incident thread that:

  • 0.35.0 was the safe version.
  • “All tags before 0.35.0” had pointed to malicious commits.
  • The restored tags were “from v0.0.1 to v0.34.0.”

That official description makes 0.34.0 the highest tag in the compromised range, not 0.34.2.

GitHub’s API is consistent with that:

  • v0.34.0 exists as a release/tag.
  • v0.34.1 and v0.34.2 do not exist as release tags.

So the post’s endpoint @0.34.2 is not supported by the repository’s own release/tag history and conflicts with Aqua’s incident comment describing the affected range.

4 sources
Model: OPENAI_GPT_5 Prompt: v1.16.0