>>> So the 
>>> plan could be along obsoleting th ecompat package with the oldest compat
>>> package not having the security flaw? Otherwise the compat package will
>>> stay happily even though it isn't anymore in the repo.
>> Yeah, that could work.
>> But I think we just need to find individual solutions for problems when
>> we hit them.
> We need a little bit if planification too.

Yes, completely agreed. But I'd like to avoid a deadlock where packages
do not enter the repo because people fear hypothetical problems. We'll
find solutions when problem comes up (just as RH sometimes has to find
special solutions). And nobody pays us for the job, so I suspect most
people won't yell at us when we say "okay, we had to update foo to
version bar which break ABI and API because backporting the security fix
was to hard"


