If somebody is going to run statically linked binaries, they would understand the security implications of that, and that they need to be able to rebuild and redeploy their binary if a security hole is discovered in a third-party library that was linked into their program.
They would already have CI/CD processes in place to rebuild the binary/container, run regression tests and redeploy the application/container to production, surely?
So what difference does it make if it's one or one hundred applications/binaries/containers then?