Alpine is out of the picture for us because the guy that works on their security tracker just doesn't care, and responds half a year after filing an issue. The tracker itself is broken for over a year and the response was to basically rebuild our own package index and host our own security tracker.
So I would not say that Alpine has security as a high priority, even though in theory there are the secfixesdb.
Redhat Enterprise, Debian and Ubuntu are used because they provide an OVAL feed that are easily integrated with zero development overhead. So if compliance is your focus, I'd heavily recommend generating an OVAL feed when you're regenerating the secfixes json files.
Source: Am building a cross-linux-distro vulnerability database and I am scraping _all_ linux security trackers. [1]