Per the Prisma Cloud scan workflow: verify registry login, registry URL, and tag before re-running the scan.

Context: Problem: The CI scan step fails before scanning starts, at image pull. Common causes: missing registry authentication (add a login step before the scan); the image_registry input does not match the actual registry URL; the image_tag is wrong or the tag does not exist; the runner cannot reach the registry (network). Verify each in order before re-running - the action surfaces which of these it hit.