Just sanity checking - if I only ever install axios in a container that has no secrets mounted in to its env, is there any real way I can get pwned by this kind of thing?
Yes. Docker breakout is a class of vulnerabilities into itself.
Yes. Docker breakout is a class of vulnerabilities into itself.