The feature sets/usage sweet points of OS-level package managers, language-specific package managers, VMs, containers, distinct/same hosts, ... are both overlapping and different enough that you need judgement to choose which one you want, but they are certainly not exclusive.
If your use case means you prefer VMs over containers and you don't need to combine them, fine, but every situation is different.
Someone with access to the docker control socket effectively has root on your machine: e.g. `docker run -v /etc:/external_etc ubuntu visudo -f /external_etc/sudoers`.
Don't let untrusted users (or scripts) run docker.
http://docs.docker.io/articles/security/#docker-daemon-attac...
Your sweeping statement applies to a minority of them.