From dev perspective this highlights that lack of embedded version control and handling of big/security fixes for any academic paper.
Dependencies that are reported to have bugs reported akin to ‘security flaws’, should lead to updates to papers with dependencies.
Naively would be good to sort references into critical references and non-critical references.