Flatpak’s use of bubblewrap (it comes from flatpak but then it became its own project) is not a good example, see:
https://madaidans-insecurities.github.io/linux.html#flatpak
But in general this is true. I talked out of memory, but firejail given its suid way is considered insecure (possible privilege escalation), that’s right



agreed, I though I ammended my original post about it.