@lanodan @nadia also, that would mean more updates that we'd get if we cared about every bullshit CVE.
And more updates => more change => harder to figure out why things broke. On one hand, it's not my job to fix outages when it's clearly the app's fault. On the other hand, it's easier to know it's not the app's fault when the app still runs the same docker image as last week.