What is semantic versioning and what does the caret mean?
Semantic versioning encodes intent in a three-part number. The major version increments on a breaking change, the minor on a backwards-compatible addition, and the patch on a backwards-compatible fix. The point is that a consumer can tell from the number alone whether an upgrade is safe.
Dependency ranges build on that. A caret allows updates that do not change the leftmost non-zero part, so it accepts minor and patch updates but not a major one. A tilde is narrower, typically allowing only patch updates. An exact version accepts nothing.
The caret is the default that package managers write, which means most projects are configured to accept new minor versions automatically. That is a deliberate trade: you receive fixes without intervention, and you depend on every maintainer classifying their changes correctly.
One rule surprises people. Below version one, the caret behaves more conservatively, allowing only patch updates, because the specification treats pre-one releases as unstable where anything may change. A dependency on a zero-point version is therefore pinned more tightly than the same range on a stable one.
The practical protection against a mistaken release is the lockfile. It records the exact resolved versions, so installs are reproducible regardless of what the ranges permit. This is why the lockfile belongs in version control and why continuous integration should install from it strictly rather than re-resolving.
The honest caveat is that semantic versioning is a convention rather than a guarantee. Breaking changes ship in minor releases by accident regularly. It is a useful signal and not a substitute for a test suite.