You should realize that this mindset created the Debian's ssl fiasco..
It's really up to downstream developers to send patches upstream giving explanation for the requested change not the other way round (there's hundred of distribution to monitors!).
So this is a process issue, not a technical issue.