Hacker News new | ask | show | jobs
by cpuguy83 2902 days ago
The main difference is the container is focused on an application and a VM is focused on a machine.

Generally the patching problem can be solved with image scanning, of which there are tools out there to deal with this, both FLOSS and pay for.