Versioning
API versions accumulate, and the old ones keep serving traffic long after everybody has moved on.
Retirement requires knowing who still calls them, which requires inventory and observability that frequently do not exist. So version one stays available indefinitely, unmaintained, alongside version four. It is a security problem dressed as a product management one.
Checked against the primary source.
