For the average developer what do I need to do? I don't use OpenSSL directly but I'm pretty sure some parts of my tech stack use it as a dependency. Do I simply need to run `apt-get upgrade` on the 25th?
Mostly, but some details matter.
Make sure that when you do the upgrade, that you are fetching the fixed version. Check for the security announcement and see which version things get fixed in:
* https://www.debian.org/security/
Once the CVE is known, you can also see which versions are vulnerable and which are fixed:
* https://security-tracker.debian.org/tracker/CVE-2020-1971
You may have to restart some services. The checkrestart utility is handy to find these:
* https://packages.debian.org/buster/debian-goodies
* https://packages.debian.org/search?keywords=debian-goodies