But I want to specifically signal a security concern to the requesting party. For example, a artifact proxy (like Artifactory or CodeArtifact) can use this response to warn developers.
For example, if we were talking about a human-readable /crates/* page, returning 410 Gone with a HTML page explaining the situation to a human, that page could have a JSON-LD snippet explaining the same to a computer.