I think this is a wasted energy, because switching cryptographic providers is the last thing you want to do under the timeline of a routine security release for an open source library.
If you're a Debian user, this might be as simple as "ensure unattended-upgrades is configured on all hosts and this is monitored somehow". However, sometimes it's not so simple.
Eventually one of these releases is going to break something that requires a code change in your applications. (Maybe pass a different flag to OpenSSL? Maybe use a different API for, I dunno, MGF1+SHA256?) And I don't know how many teams are prepared for that kind of rollout.
I'd be interested in hearing from HN users how they plan to respond to these sort of releases.