The killer for me was I couldn't find a single attempt by Debian to update the package as a security update. They just let it die and recommended everyone install the unstable package. I found it highly unpleasant to install a single unstable package to get my email server running again (I didn't want to disable virus scanning). If killing the signatures database doesn't count as a security update, what does?