Scan DAST's Public Release Container Images

Currently the container_scanning job runs on every commit of the main branch of Browser-based DAST. The job scans the latest (edge) release, both FIPS and non-FIPS.

We should add a container scanning job that scans the version tagged images i.e. the publicly released images. Reasons to do this:

  1. Better for FedRAMP compliance so that only the released images are scanned.
  2. Correct attribution of the found CVEs to the version of Browser-based DAST in which they were found.

The job should run after the release job runs in the pipeline.

Edited by Arpit Gogia