RFC: A new versioning strategy for Discourse

What is the protocol in regards to backporting security updates to ESR versions? In particular, dependency version updates. Our site is currently running on v2026.1.3, with an upgrade to v2026.7.2 happening soon. Looking at security scans and vulnerabilities being flagged, and cross-referencing package updates in monthly releases that resolve CVE’s, I’ve noticed updates that aren’t making it to the ESR version.