I think the parent comments point was that it’s difficult, if not impossible, to verify the security of even a particular hash. It’s still vulnerable to the same dependency chain vulnerabilities as pinning to latest, but instead locking in a particular version and _hoping_ that it wasn’t pwned. Additionally, you are then not getting any exploit fixes that may be included in newer versions, so even if there was a vulnerability you are now stuck with it until you decide to manually update.
To be honest if you’re that concerned with dependency attacks like that then you should just be hosting your own image registry and building your images yourself, and then only being vulnerable to dependency attacks within the OS distributions and such.