Sorry, this analogy does not hold up.
First of all, you're comparing unintended software vulnerabilities to physical locks; being able to open a lock with a lockpick is an element of the design! Everyone knows this going in!
That aside, ask yourself what car manufacturers have to do to prove the safety/security of everything in their supply chain down to nuts and bolts, and what the consequences are when they make a mistake.
Now compare that to how modern consumer software projects do dependency management and verification, and what happens when they have a whoopsie because some open source library they pulled from GitHub with a "no warranty" license exposed them to a critical data breach. In my experience they throw their hands up and say "meh sorry, software is hard."