Updated motivation for supporting secp256k1

Considering bitcoint/secp256k1 doesn't offer versioned or even tagged releases, it seems unsuitable to use it as a dependency, if a dependency outside of BoringSSL is even on the table. How is that library supposed to be consumed?