Mounting /var/run/docker.sock into a container to let it build images is equivalent to giving that container root on the host, and it is presented in most CI documentation…
Removing personal data at the call site catches what you thought about; removing it at the shipper catches the debug line somebody adds next year in a code…
An image with no shell, no package manager and no coreutils has a very small attack surface and is genuinely unpleasant the first time something goes wrong inside…
Passing a private repository token as a build argument puts it in the image history, where docker history will read it back out for anyone with the image.…
The argument has been technically optional and omitting it means no authorisation at all, which is how an endpoint intended for the admin ends up readable by anyone…