Kyverno policy tests don't include ephemeralContainers
Looking through some of the test manifests and seeing that ephemeralContainers aren't being used as a target in some of the policies that look at container security (e.g., disallow-privilege-escalation).
It appears the corresponding policy would cover ephemeral containers, so this is really just a testing gap. I didn't comb through all the policies/tests to verify though so might be good for someone to do.