Your changes can't hurt me!

curl upgrade news. Highlighted text:  - The curl CLI is now back to using OpenSSL, instead of GnuTLS. The curl CLI is now using GnuTLS instead of OpenSSL. Image of Neo dodging bullets
you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 1 year ago

That's another option, but it's a bit more cumbersome having to cherrypick which exact backports you need for your specific hardware. Also, if you then for some reason don't upgrade to the next stable release when it comes out, backports get abandoned after 1 year instead of the customary 3 years for the rest of the oldstable release.

From my experience, running trixie/testing the past year or so on a minipc with hardware that was a bit too recent for bookworm, I can say that the cadence of security patches has been about the same between bookworm and testing.

And let's be honest, on a desktop system your main attack surface is going to be the software you go online with, i.e. the browser. So if you make sure that is kept up to date (flatpak, vendor repo, ...) that already goes a long way.

  • source
  • parent