Give it time.
The industry is also still refusing to learn that the dependabot model of instant dependency bumps by now is a hazard, given that supply chain attacks are usually more likely than missing out on security fixes.
I like your idea