Why not pin your packages? Andnwhy not have M of N auditors sign off on releases?