At the end of the day you have to trust someone (Bitwarden, Hoster, Hardware Manufacturer…). It comes down to your threat profile and what you personally accept as a risk vs. effort (or convenience). For me Bitwarden was acceptable, but I switched to self hosting Vaultwarden ca. 3 years ago. Main reasons being the advanced features (sharing some passwords with the family, setting up a tech savvy friend to take over my vault should I get hit by a bus, etc.). I did not have any relevant downtime of that service in years.
Years ago I consulted for a French company and analyzed their processes. Heavily depended on Excel. They all pronounced Excel Sheet as “Excel Shit”. All day long it was sentences like"…and then I make an Excel Shit here", “… then I give the Shit to my colleague”. It was glorious… (and technically they were right).
Wow, thanks for all the great answers so far. As for why not latest:
So, probably a combination of latest for low criticality and pinned on critical stuff (e.g. authentication, access, etc.)