In light of the latest BASH exploit I've been patching and updating things.
Someone pointed me to Vultr and their approach where it appears they maintain inside the container access:
Appears they have unattended security updates inside folks containers if others are reading correctly and so am...