Signing images and requiring that the bootloader can't flash anything else is just vendor lock in / ceding your power as an end user. It doesn't make you more secure in any way since a bad actor will figure out a way to bypass making writes to the system partition.
Umm I remember ordering Chinese phones way back when (think android 4) with unlocked boot loaders - both had some random junk installed via custom ROM and you couldn't uninstall it.