cool! happy to hear that. if you have any ideas or comments about Kubescape, we would love to hear them
If you could check for container signing and providence on all materials and make sure that only a single registry is being used (ex only `internal.company.com:443`) and make sure it's not possible to schedule pods with unsigned/untrusted containers that would be awesome.