One idea was to use docker binary packages. However, docker binaries are statically linked and are incompatible with devicemapper. See https://github.com/docker/docker/issues/14035 for more info. Holding will let the user turn on automatic updates for non-security packages as well. Fixes #183