I think that behavior is totally fine, but only if the change is communicated to the people using the program or library.
I had an interesting issue with Nuget package manager. Authors of some open-source package we’re using changed their license from permissive MSPL into another one which only allows non-commercial use and also says “reserves the right to modify this Agreement at all times without notice”, LOL.
At some point, I pressed a button in visual studio to upgrade dependent packages if our software. The project it relatively large. It’s developed by a team of people over years, and has dozens of dependencies. The project builds a desktop software which doesn’t listen on any sockets or installs any services, security is not an issue, so I only pressing that button couple times a year. A few of these third-party libraries were automatically updated. I have built and tested the software, and called it a day.
It was mere luck I noticed the change of the license of that library before we built new public release of our software.
Not sure everyone agrees, but I think the responsibility is largely on Microsoft, not the package authors. When a package author changes their license to be more restrictive, I would expect Visual Studio should stop upgrading the dependency, and show the developer doing the upgrade some message box with human-readable error text, and links to old and new licenses. That didn’t happen, it was no popups, no messages, nothing I could possibly notice and react.