fast-nail-55400
03/02/2026, 5:21 AME native_engine.IntrinsicError: Client error (404) downloading file trivy_0.57.0_Linux-64bit.tar.gz from <https://github.com/aquasecurity/trivy/releases/download/v0.57.0/trivy_0.57.0_Linux-64bit.tar.gz>
https://github.com/pantsbuild/pants/actions/runs/22559982451/job/65345984543?pr=23121#step:12:556
https://github.com/aquasecurity/trivy/releases/v0.57.0 doesn't have any assets in it besides the usual source code archive.fast-nail-55400
03/02/2026, 5:31 AMpull_request_target workflow: https://github.com/aquasecurity/trivy/discussions/10265fast-nail-55400
03/02/2026, 5:31 AMfast-nail-55400
03/02/2026, 5:51 AMfast-nail-55400
03/02/2026, 5:51 AMwide-midnight-78598
03/02/2026, 12:16 PMwide-midnight-78598
03/02/2026, 12:24 PMpull_request_target - I thought Github made changes to prevent some of the threats on that vector, but maybe I imagined it.
Pants uses that too in a couple of places with a security note - but I dunno, the fact that so many GH attack vectors start with that specific job 🤷wide-midnight-78598
03/02/2026, 1:18 PMError: io: Peer disconnectedhappy-kitchen-89482
03/02/2026, 9:25 PMhappy-kitchen-89482
03/02/2026, 9:25 PM