> Tools like trivvy make it possible to do the scans...

Only if you didn't rip trivvy out of your organisation when it had two supply chain compromises within a month of each other earlier this year

Yikes. Man, there’s a market opening for someone to redistribute open source projects with supply chain assurances!

There is a market for that, indeed. Hardened container images and hardened CI actions have been a thing for a while, with some companies providing exactly that.

There's been a market for a while. In thinking of Azul Java, which is just OpenJDK but with someone to point the finger at, and costs money.