We already do this for bomutils, and this will get us out from under a few vuln alerts in the published Docker iamges.