Huh what's the benefit

It's a hardened, security-first implementation. WASM runtime specifically is for isolating tool sandboxes

WASM has issues with certain languages, why WASM and not OCI?

Docker is not a security boundary?

[deleted]

That's defined in context, security is a spectrum with tradeoffs

OCI supports far more and has a much bigger ecosystem