I've been instituting exactly this kind of cooldown/delay on dependency updates at all of my clients for four or so years and I'm glad to see more people talking about it: https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns