I am getting the following error on boot:
[ 0.033460] [Firmware Bug]: TSC_DEADLINE disabled due to Errata; please update microcode to version: 0x52 (or later)
[ 0.117431] SRBDS: Vulnerable: No microcode
Searching for the error indicates that I should install intel-microcode.
It would probably also make sense to include the AMD equivalent: amd64-microcode
My proposal would be to add these package to the image.