"in practice they are more insecure because of the bullshit update mechanisms."
your argument is bullshit.
90% of the webservices i run do maintain their own Dockerfile and/or docker images on hub.docker.com
peertube updated their development images 3hours ago.
"Last pushed 3 hours ago"
https://hub.docker.com/r/chocobozzz/peertube/tags
---
peertube uses the latest official debian image. they get updates as soon as new versions release.