A container tag is a mutable reference. myapp:v1.2.0 can be repointed at different bytes at any time, and nothing in a Kubernetes deployment referencing that tag will tell you it happened.
Deploy by digest and "what is running" has exactly one answer. It also makes rollback a redeploy of a known artefact rather than a rebuild and a hope.
The objection is that digests are unreadable. True, and irrelevant: no human types them. CI resolves the tag to a digest at build time and writes the digest into the manifest. The human-readable tag stays as a label for people, and the digest is what the cluster pulls.