I have high hopes for Debian GNU/kFreeBSD - the FreeBSD kernel with the Debian package management.
I have high hopes for Debian GNU/kFreeBSD - the FreeBSD kernel with the Debian package management.
# portupgrade -rvP --batch foo-1.2.3
This will upgrade installed package foo and anything that depends on it using binary packages from the mirror site, falling back on a build from source.Installing a new binary package:
# portupgrade -vNP bar/baz
If you're using portaudit to stay on top of vulnerabilities (it's part of the default install these days), here's a nice way to upgrade everything: # portaudit -a | sed -ne 's/^Affected package: //p' | sort -u | \
xargs portupgrade -rvP --batch
I'm like you, for some vulnerabilities I don't want to upgrade a ton of stuff. FreeBSD is perfect for this though, you can just pop into the port directory, "make extract," apply the patch, and "make reinstall." You can avoid full rebuilds by always passing "-W" to portupgrade whenever you install / upgrade stuff.For example, take a Firefox or PHP security vulnerability. Those projects generally don't just release a new version with the security fixes; they'll throw in whatever feature changes they've made along the way. I don't want to sort through the various changes and patches to find the right combination; trust me, it's no fun, I worked on the Debian security team for a while. It's important to me to get just the security fixes because I don't have time for a constant upgrade treadmill and there will be new bugs in with the new features.
I really want my operating system to just work and get out of the way. If I didn't need any packages from ports, I think FreeBSD would fit that bill.
Also, in 7 years, I've never had package updates break things on OpenBSD (aside from config file formats changing or postgres database transfers, with warnings at update). That happened to me a couple times with Debian (around woody).
* except for my ports that haven't made it upstream yet.