Most of the risk lives in layers you did not write. Moolé x-rays all of them.
Your code is a thin slice on top of language libraries, system packages, and a full base OS. Here is where the CVEs actually live.
Most tools scan your code.
Moolé scans everything under it too.
Every layer read, then matched against your cluster to see what is exposed and reachable.
Reads every package across all layers, and connects to your registry directly: Amazon ECR, Google Artifact Registry, Docker Hub, Azure, Nexus.
Identifies the true base OS from the filesystem, not a label, so a quiet base-image swap does not slip past.
Maps each vulnerability to the pods and namespaces running it. Findings no workload reaches drop out of the way.
Catches poisoned images and dependency-confusion attacks, where a bad package matches the name of one you trust.
Same image watched at every stop, with enforcement at the registry, before a bad build reaches the cluster.
Fail-build only on policy-breaking, reachable risk, with reporting mapped to the frameworks auditors ask about.