Docker Scout D → B. OpenSSF Scorecard 7.8/10.
My aws-kubectl (700K+ pulls) now ships cosign via Docker + Sigstore, SPDX SBOM, SLSA provenance, non-root default, immutable tags.
Framework + the 4-hour incident:
https://heyvaldemar.com/docker-supply-chain-hardening-solo-maintainer/










