Strings are immutable on the Python side. On the C size, however, PyUnicode_Resize is part of the PEP 384 Stable ABI and very specifically tries to resize the string in-place (it's normally intended for string-building).
If it is immutable from the client’s perspective, it’s immutable. Anything else is ill-defined.
The C api is “from a client’s perspective”. Any rando can build native modules with it.