3 ms·
If you run Debian stable (or oldstable), you only get back-ported bug fixes, and no new features-- the upstream versions of the packaged software are "frozen" b
by sillystuff 5y ago
If you run Debian stable (or oldstable), you only get back-ported bug fixes, and no new features-- the upstream versions of the packaged software are "frozen" before each new major Debian release.
So, you don't get a million updates caused by exactly tracking the upstream. You only get the updates necessary to address bugs.
A huge upside of this is that you don't have to worry about breaking changes until a major version upgrade. E.g., some years ago upstream TCL changed its default from blocking to non-blocking I/O. I had to change nearly every TCL script I had to account for this change after dist-upgrading to the new Debian version. It was nice to not have a breaking change like this occur with just some random automated update.
If you want Debian + rolling release, there is testing and unstable. But, packages in testing only get security patches when they trickle down-- there is no explicit security patching for testing. E.g., I wouldn't run a web browser or other security critical software from the testing release where it is exposed to the outside world. Probably safer to either run sid/unstable for a desktop, or careful use of pinning. For my own desktop, I've been running Bullseye testing, but pin Firefox back to Buster since it doesn't have any library conflicts.
Firefox and Thunderbird are handled differently. These packages track upstream ESR versions in Debian "stable", and the version can change in the course of a stable release.