Hello,
In reference https://twitter.com/adobrawy/status/719766243016880132 I suggest add note about pull requests updater for pinned dependencies eg. pyup.io, requires.io which prepare pull requests which up-to-date packages. It was integrating very well with continuous integration service eg. Travis-CI, so effort less you can stay up-to-date and pinned packages.
I believe this is very import to update python packages due security vulnerabilities. If updates are made easier to be performed then will be done more frequently which improves overall software security.
Greetings,