I thought the "hardened images" were a step in the right direction. It's a pain to have to deal with vulnerabilities on ephemeral short-lived containers/instances. Having something hyper up to date is welcome.
https://www.docker.com/blog/introducing-docker-hardened-imag...
Could be, I have to see it before I believe it. This container tech is too fragile.