Most ROMs are based off of either AOSP or lineage. The list of unofficially supported devices is huge. Since, most devices share the same SOC's they're usually just forked off of each other with gradual tweaks. The Sony open device project is semi supported by sony but doesn't share any code with the stock images.
So, that really just leaves the bootloader. How much attack surface does the boot rom actually provide? I feel like most vendors would probably just assume a backdoored system or boot partition. Your boot rom would have to accommodate for all kinds of potential Android versions. It sounds like a lot of effort for a corner case so not really worth the effort.