Following up on this discussion - my security issue was closed - opinion was its not jenkins problem its Debians problem :facepalm:
but I did some more testing regardless -
JDK11 - 2.267 - 13 Medium findings + 89 others (Debian Stretch based)
Alpine - 2.267 - no findings - container is clean
Centos (8) - 2.267 - no findings - Container is clean
Default jenkins/jenkins - 2.266 - 9 high - 17 medium - 37 low - 70 informational - (Deb stretch 9.13)
These results are all with AWS ECR scanning which uses Clair scan rules