@elazar @seldaek Doesn't this imply that your top-level libraries will have to release a new version every time a downstream does?
So for Lippupa to get 0.7.9, which has a critical security issue, it will need to release 1.2.4
That's a lot of onus on the maintainer.
Or did I read this wrong?