Removing a security scheme should IMHO not be considered incompatible, as the API should still accept requests with the old security scheme applied. If this issue is accepted, I'm happy to provide a PR.