Supply Chain Visibility
Production images should be scanned for known vulnerabilities and unnecessary packages. Modern Docker tooling can also generate or inspect software bills of materials (SBOMs), which help identify what components are inside an image.
Scanning is not a one-time activity. Rebuild images regularly so patched base packages can be incorporated.