• SayCyberOnceMore@feddit.uk
    link
    fedilink
    English
    arrow-up
    5
    ·
    15 hours ago

    It’s difficult to do security-only updates when the fix is contained within a package update.

    Even Microsoft’s security updates are a mix with secuirity updates containing feature changes and vice versa.

    I usually do an update on 1 random device / VM and if that was ok (inc. watching for any .pacnew files) and then kick Ansible into action for the rest.

    • quick_snail@feddit.nl
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 hours ago

      Why does unattended upgrades with security only setting not fix this?

      This is literally why Debian has distinct repos for security updates.