The defaults, and why
Image versions are pinned to a major version, so a pull never jumps to a new major release on its own. Data lives in named volumes, so removing a container never deletes it. Passwords come from a .env file, kept out of the compose file and out of version control.
Databases and caches are not published on a public port. Docker's published ports bypass UFW and most host firewalls, which is how many exposed Redis and MongoDB servers are found and taken over. Services reach each other by name on the project's own network; if you need a database from the host, the port is bound to 127.0.0.1 only.