TLDR: Ubuntu Pro offers additional security patches to packages found in the universe repo. Universe is community maintained so Ubuntu is essentially stepping in to provide critical CVE patches to some popular software in this repo that the community has not addressed.
I suppose it depends on how you look at it but I don't really see this as withholding patches. Software in this repo would otherwise be missing these patches and it's a ton of work for Ubuntu to provide these patches themselves.
Now is they move glibc to universe and tell me to subscribe to get updates I'll feel differently.
Ruben isn't super quick to put out updates but he makes up for it in quality. He was slower than some other devs to get Boost for Lemmy out the door but the first release was damn near perfect, stable, fast and only very minor bugs. Personally I prefer quality over constant updates.
These developers owe us nothing and it takes an incredible amount of time and lots of money to develop an app of this quality so no matter which app you choose consider paying and/or donating.