```python
"""Vet a device's proposed firmware upgrade path and report the final tag."""

import re

def vet_upgrade_path(installed: str, steps: list) -> str:
    # Validate the installed tag
    if not isinstance(installed, str) or not re.match(r'^\d+\.\d+$', installed):
        raise ValueError("installed tag must be a string of two dot-separated numbers")

    # Validate each step in the steps list
    for step in steps:
        if not isinstance(step, dict) or len(step) != 2 or "tag" not in step or "requires" not in step:
            raise ValueError("each step must be a dictionary with keys 'tag' and 'requires'")
        if not isinstance(step["tag"], str) or not re.match(r'^\d+\.\d+$', step["tag"]):
            raise ValueError("tag must be a string of two dot-separated numbers")
        if not isinstance(step["requires"], str) or not re.match(r'^\d+\.\d+$', step["requires"]):
            raise ValueError("requires must be a string of two dot-separated numbers")

    carried = installed
    for step in steps:
        if carried < step["requires"]:
            raise ValueError(
                f"step {step['tag']} requires at least {step['requires']}"
            )
        if step["tag"] <= carried:
            raise ValueError(f"step {step['tag']} is not an upgrade from {carried}")
        carried = step["tag"]

    return carried
```