In practice, in the case of less popular packages, they do this on demand, when someone requests it in the bug tracker.
I want to emphasize that we have no contact at all with the people maintaining that Debian package, they've never reached out to discuss anything. We're absolutely open to that (and they know where to find us, not hard to contact us either on GitHub, Twitter, our forums, here, etc).
They will contact you if the need arises. It's the same usual process that has been used since the 90s to great success.
It's ok to not want to support older versions or downstream packages (even if imo there is value in doing so) but don't be a drama queen and claim you can't.
Maybe. That is indeed a risk with third party distribution.
But do note that Debian has its own support channels, and infrastructure (like the "reporting" tool: https://packages.debian.org/stable/utils/reportbug ).
Maybe it's pretty good for very popular packages, but how about the more niche ones (and when it comes to Debian I'm not sure how popular Caddy is in their view)?
The versions often feel arbitrary and don't line up. For example... I've been watching this for years:
https://bugs.launchpad.net/ubuntu/+source/firewalld/+bug/183...
This is more on the edge case side of things, too. Not really security patch related -- but a consequence of picking/choosing component levels
With this the firewall can randomly just stop being effective
When things aren't exactly upstream, the knives you're juggling get a little bigger and more unbalanced.
That's exactly why people (including me) tend to like LTS - no critical changes till next release. Upgrades for security with minimal surprises. I go further and often use unattended-upgrades on my Ubuntu fleet. I don't wanna version bumping until I explicitly ask for it as much as possible.
In two patch versions? With minor version unchanged?