Trivy supply-chain attack spreads to Docker, GitHub repos