Your image scanner tells you what you shipped. It cannot tell you what the container runs now.
A scanner reads the image: the packages and binaries baked in when the build finished. That is the right question to ask.
#ContainerSecurity #VulnerabilityManagement #RuntimeSecurity