Which would be the best/recommended ways to compare the official images to their hardened versions, and could most of the differences be baked into the original images by default? Wondering specifically about something like postgres.

nvm... seems like 'docker history' should work to compare images