Is your feature request related to a problem? Please describe.
There are use cases where we don't want our images to be published to the canonical docker registry (e.g. internal services). Oci-factory provides some useful reusable workflows for building and testing the image, BUT the workflows for scanning for CVEs and notifying (either through MM or gh issues) are not easy to reuse.
Describe the solution you'd like
It would be nice if the workflows for vulnerability scanning (and releasing?) were refactored so that they could be used from other repos.