This is a real world trolley problem scenario. You can break workflows or you can let everyone get pwned by supply chain attacks. Which is the greater harm?

People will not adopt a safer version if it broke their workflows. Adoption is part of preventing supply chain attacks.

They will if it's the only version. Eventually.