> what is way bigger now is the number of packages carried back from the Debian base image (required to use PyTorch instead of Alpine), to be more precise 429 packages with an insane number of known vulnerabilities, even if this image is the latest stable Python 3.11 release.
Most security checking tools are incompatible with how Debian (and Ubuntu) deal with security issues: they backport security fixes to existing packages shipped with their stable distribution releases (so you'd have openfoo-1.4.3-debian4 instead of eg. openfoo-1.5.1, yet it wouldn't be vulnerable even if 1.4.3 upstream was).
While there is a caveat about false positives, I think it's irrelevant in the context of Debian since I trust Debian more than the tool author used.