Firstly:
company-specific base image = base image + company-specific source code fileIn
Why could we not be completely sure that company-specific base image + source code fileIn didn't "contain things it shouldn't" ?
Secondly:
> … also things in the original images of the commercial STs that one would or should not ship with the product.
That doesn't seem to be an example of "You could never be completely sure that it didn't contain things it shouldn't."
That seems to be an example of you being completely sure.