Software vulnerabilities are often not placed maliciously, and are present in the original source. If you don't patch them if discovered later, you'll be vulnerable to them.
> your own repo reviewing and merging from upstream as needed. Would be a giant PITA though