It's generally best to get a phone that receives software updates and security patches for more than 2-3 years.
See first paragraph again, not everybody is as affluent as you're, look at the problem from the other perspective
Additionally, threats can come from various sources like:
malicious apps,
will take control of the phone from the inside out, nothing will withstand that
texts,
Pegasus will use 0day, nothing to do about that
USB devices, or physical access,
Once somebody have physical access because you're some POI and not an average Joe, not much you can do
Choosing a manufacturer that supports phones longer can help reduce these risks over the life of the device.
See first paragraph, parenthesis content. Also phones are made with short lifespan on purpose, this gives steady inflow of money for the manufacturers, only few will give you what you want
I guess if you're broadcasting all the beacons your phone can be pawned even if you miss the last month OS update on your latest, greatest, shiny toy. This is just inevitable.