https://github.com/opencontainers/runtime-spec/blob/main/features.md should return the list of unsafe annotations. (“org.systemd.”, “run.oci.”, etc.) - https://github.com/opencontainers/image-spec/pull/1061/files#r1194531089