HI @ashley,
A package's unlisted state (i.e. "yanked" in PyPi or Ruby) is server-side metadata, similar to download count. That means, once a package moves servers (i.e. from pypi.com to ProGet), that metadata is owned and maintained by the new server. When a package is cached/pulled into ProGet, that state is copied from the remote server.
An unlisted/yanked package may still be downloaded and consumed, and it's up to the client to determine how to use (or not use) packages with that status. ProGet simply displays an "hidden icon" next to unlisted packages. Visual Studio does not display them at all. I would imagine pip doesn't consider them in dependency resolution and might give a warning if consumed directly.
That said, the OSS Metadata Updating & Caching will routinely sync Listed and Deprecated statuses, but it comes at an obvious performance cost. Or you can use retention policies to more aggressively delete cached packages.
Hope that helps.
--Dean