but, you also have to like, consider that semver is primarily a way of communicating breakage. and so like, you could actually argue that if the security issue is bad enough, a semver-minor release that breaks is better than the above, because you want people to get the fix more quickly