@federicomena I don't know of that document, but I think there's an interesting way to extend that analogy.
Each of those containers uses the libraries slightly differently, and thus creates a kind of biodiversity. So if a vulnerability exists, but only if you use a certain way, that could be a critical issue for one package but not the other. A distribution would have to assume worst case of how programs use it, but individual packages don't.