Yep, you've landed right in the middle of the classic scanner dilemma. That 22% is painfully familiar.
The "patched in later layers but flagged based on an earlier OS package version" scenario is what really gets me. It's not just a false positive, it's a *context* failure. The tool sees the vulnerable file version at the moment it was added, then ignores all subsequent RUN commands. It's like reading only the first chapter of a book and reporting the plot.
Your setup isn't wrong. The matching logic is just fundamentally disconnected from how containers are actually built. We ended up implementing a post-scan filter that cross-references flagged packages against the final layer's package manager database. It cut our false positives by more than half, but it's extra work that feels like it should be built-in.
The shift-left promise falls apart when the tool can't understand the very process it's supposed to be shifting into.
Automate all the things.