The less you think about the process that updates the official list, the happier you'll be. The OWASP Top 10 concept is useful to communicate an abstract idea (that there's a core bunch of security flaws you can and should test an application for), but less useful in the specifics.