This is a great idea...unfortunately a company that skips on Django security patches and bug fixes will very likely be doing the same for everything else (frontend libraries, servers, etc). But there's not much you can do when you're stuck on a feature-factory treadmill, and this looks like a cost-effective way to ameliorate the problem.