Updating every dependency for every kind of CVE is a brute force method for people and organisations that don’t understand the attack surface of the programs they’re producing
Who is doing what you’re describing? The reason I can confidently freeze and offline stuff is because I’m not taking in whole frameworks, I’m selecting things carefully, and generally do end up reading at least most of the source
And what ‘monitoring’ are you going to be doing besides things like CVEs?