> I want to update my dependency for my tiny service for a security patch
If the API changed it's not a security patch... Why would a change that only fixes a security bug cause tests to fail?
Sounds like this is more a matter of needing to cherry-pick temporarily and then actually pushing for the codebase to update, probably by the security team.
Sometimes you need to work with other people, that might necessitate doing "ugly" things to get the job done.