TL;DR: The tag does not exist. List the available tags (Docker Hub Tags page, or `crane ls` / registry API) and pull one that does, e.g. `docker pull myimage:1.2.3`. `:latest` is just a tag like any other; if the maintainer never pushed it, it does not exist.

## The error

```text
Error response from daemon: manifest for myimage:latest not found: manifest unknown
```

## Fix it

1. List real tags:
   open the registry Tags page, or `docker buildx imagetools inspect myimage` to probe.
   Expected: you see which tags actually exist.
2. Pull an existing tag:
   `docker pull myimage:1.2.3`
   Expected: succeeds.
3. Fix the Dockerfile or script referencing the bad tag.

## When this applies
- Typos in tags, or assuming `:latest` exists
- CI pinning a version the maintainer renamed

## When this does NOT apply
- "pull access denied" (auth/name problem)
- "no matching manifest for ..." (arch problem, tag exists)

## Versions
All Docker versions.

## Why it happens
Tags are mutable pointers; the daemon asks the registry for the manifest digest of your tag, and the registry 404s when no manifest is filed under it. The name can be perfectly valid while the tag is fiction.

## Edge cases
- Rebuilt tags: the digest behind a tag can change; pin digests (`image@sha256:...`) for reproducibility.
- Some registries are case-sensitive on repository names; a case mismatch can surface as manifest unknown rather than access denied.
- `latest` is not special; many official images do not push it for major versions (e.g. postgres:16 vs postgres:latest both exist, but not for every image).
