If it were mutable, the author would need to revoked and reissue which would notify the users who installed the incorrect version.
I'm coming around to mutable. You wouldn't want to have to revoke a release to fix a typo in the change log. Clients could also keep track of the version they installed from and notify the user if a new version comes in with worrying changes in it.