I’ve been testing Dockhand’s vulnerability scanning in my home lab. It can scan a newer image with Trivy or Grype before it does an automatic update to replace the running container. You can also block the update based on the rule you choose which I think is pretty cool. I wrote up a post on configuring this setup and the rule you can choose. Curious how others decide which container updates to automate in your home labs or production?