If they just pull patches from the community themselves, when something goes wrong they will have to take the blame themselves and people will think they are foolish being so reckless. As a techie, this option may seem feasible to you but then again you're just some random guy on HN who probably thinks node.js is the be all and end all of IT. I doubt you've got the intelligence (cleary) or the experience (very cleary) to understand how the IT industry works at a human, risk management and legal level.