I beg to differ. Since 2024-06-07 Let's Encrypts ACME server did not serve any chain which included the now-expired ISRG Root X1 cross-signed by DST Root CA X3 intermediate certificate.
This date was explicitely chosen to be at least one lifetime of Let's Encrypt certificates, which is 90 days, before the cross-signed intermediates expiry. Thus anybody relying on the DST Root CA X3 should have gotten at least one certificate renewal with a chain which was not cross-signed by DST Root CA X3 before the actual expiry date of this cross-signed intermediate. Unless one would manually change the chain to include this cross-signed intermediate, but then one would assume that person actually knows what they're doing and would know about the upcoming expiration.