When a vulnerability is discovered we could try to perform the update in the manifest file.
Starting with Ruby or Javascript (since the manifests are usually easier to understand) we could try to change the vulnerable version for the latest minor that matches the user current dependency.
e.g. depspy fix