Step 1
Choose scanner image and first target
Use a deterministic target and a known scanner image so results are easy to validate.
- Use `secplatform/pipeline-scanner:latest` (or your mirrored public ECR alias) for first run.
- Pick a known target such as `python:3.11-slim` for predictable first results.
- Run Trivy or Semgrep in JSON mode supported by the scanner client.
- Keep branch, commit, or artifact metadata for troubleshooting.