Nope it isnt, its up to me as user to decide when to update, what Signal/other-app can do in such case is provide a simple in-app messaging system "Hey there was a vulernaribility, read more about it here in this message". Then user can decide.
And not "hey user, take this update which contains backdoors since the main developers got gagged/blackmailed, trust us this time for real".
In a security sense, this is actually a very real concern with which even a warrant canary cannot help. Could you provide hard evidence that Signal's developers have NOT been "gagged" or "blackmailed"? I think such a proof would be infeasible at best.
And not "hey user, take this update which contains backdoors since the main developers got gagged/blackmailed, trust us this time for real".