CLI v0.615.0 has been released with the following fixes:
• Trivy is no longer enabled by default when generating a new qlty.toml
• Unpinned Trivy usage will now automatically use v0.69.2, the latest available release
If you have Trivy pinned to a specific version in your .qlty/qlty.toml, you will need to either update it to 0.69.2 or disable the plugin until the upstream situation is resolved.
For more details on the upstream incident, see the Trivy security incident report: https://github.com/aquasecurity/trivy/discussions/10265
Trivy experienced a security incident on 2026-03-01, which resulted in GitHub releases between v0.27.0 and v0.69.1 being deleted, causing build failures for any project using an affected version of the Trivy plugin.
Workarounds:
• Pin Trivy to v0.69.2 in your .qlty/qlty.toml
• Or temporarily disable the Trivy plugin until the situation is resolved
For more details on the upstream incident, see the Trivy security incident report: https://github.com/aquasecurity/trivy/discussions/10265.
With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.
Start free trialNo credit card required · Cancel anytime · 6020 services available
Integrations with