Hi Timothy,
Many thanks for pointing this out! We should put this somewhere to Wiki, in VERY LARGE letters as over the years I'm also very sensitive to all the people not liking to do their microcode update.
I always failed to explain that microcode is not a program (despite the "code" in the word). I concluded that people are preventing doing the microcode update because of religious reasons as I failed to identify any other reason. I also do think that if one trusts the CPU one should also trust the update, otherwise it makes more sense to go for RISC-V CPU in FPGA approach.
Thanks Rudolf