Do not pull in latest selinux-policy updates
Pulling in selinux-policy updates could potentially trigger new avc denials before we had a chance to mask/report them. Instead this should be done as part of the compose update process when we test updated userspace.