I would love to be able to answer that first question for you. Unfortunately I have nothing to share yet.
My understanding is that HSTS carveouts are supported by Chrome but not yet other browsers. There's more standardization work to be done there. That said, you can only request entries on the HSTS list for domains that you own, and since no one (yet?) owns any .dev domain names, no one could request such changes. It goes without saying why you can only change security settings for domain names that you own.
And for the last question: Again, there are no .dev domain names. There never have been. It's never been available for registration. The recommendation for a long time has been to only use either (a) domain names that you actually own, or (b) domain names that are reserved for testing and are guaranteed never to exist a la RFC 2606. Using domain names for testing that don't yet exist but could in the future is a huge security hole that you must fix now. Do it now while the domain names still fail to resolve. Once they resolve, and you don't own them, then your security situation gets a lot worse.