I also think this really shows the disconnect in mentality between the younger developers and the 'older' ones (I quote this because while I am 25 I often find myself in the latter category).
Software used to be a thing you maintained, if you made a major release you would continue to support the old one for a period until users (in the case of libraries, developers are your users) had a chance to migrate off of it. This meant releasing security updates and bugfixes for the old release in parallel to the new one - or at least making it not impossible for these changes to be backported.
Now everyone wants to be evergreen - you're still using 1.2.x of my library that has glaring security issues that have been fixed in 2.x? Well, better upgrade, because I'm only supporting the newest release.
As someone who has to constantly deal with the headache that is NuGet for their day-job, I absolutely loathe this mentality and the idea that everyone should just use their language package manager. If any of the NuGet packages we use internally has some glaring security issue, I've got 20 applications to update, test and redeploy on a good day if there's no breaking changes - at least if for whatever reason the Fedora packagers can't backport a security fix for a python package I depend on it's easy enough to push a new version out in my local yum repository and have it automatically fixed for every application that uses it.