WASM has issues with certain languages, why WASM and not OCI?
Docker is not a security boundary?
That's defined in context, security is a spectrum with tradeoffs
OCI supports far more and has a much bigger ecosystem