Let's say a company's app has a security vulnerability. Let's consider 2 scenarios: (A) using Angular vs (B) using an internal framework.
From engineering perspective it doesn't matter if it's (A) or (B). It's not like the internal framework will be perfect and bug-free.
In both cases it is company's responsibility to patch their app. In case (A) they can fix it in their internal fork of Angular; or fix it upstream; or update Angular to an unaffected version. In case (B) they have to fix their framework.
You stated that:
> When a company decides to use Angular (for example), they're also deciding to jump on the rat-wheel that is constant upgrades to the next version.
> Meanwhile, that vanilla app will just keep working in perpetuity.
and I disagree with it.
If a company doesn't care about security, they can have Angular "working in perpetuity" as well as their vanilla app.
If they do care about security, their vanilla app will not (securely) "work in perpetuity" since it will need a fix sooner or later.