I would call that stagnant rather than stable. If a version of software remains the same with the same bugs/issues not getting resolved, that seems unstable to me. Yes, not crashing could also be considered stable as well.
In Stable (what you call Stagnant) vulns get backported. Only the code fixing the vulnerability gets updated, the rest is left untouched. Its how Apple deals with older iOS versions, and it keeps their happy users of older devices happy.
If I run some old piece of hardware/software, there are a few things I want: I want it to keep functioning the way I bought it, and I want it to remain secure and reliable. So what I want is security and reliability fixes ie. what Debian Stable (and e.g. Ubuntu LTS) receives.
This isn’t always possible. And sometimes creates more problems than it solves or ends up not mitigating the issue completely.
In any case, backporting is a slower process. And back ports for non-stable are not done by the security team but volunteers.
....what. That is not how OS stability works.
Also, Arch is nearly impossible to use in production environments.
Let's say there is a vulnerability discovered in the version of lighttpd you're running in your production environment. On Debian, you pull that package, do some testing, and you're done.
On Arch? It's a rolling release distro. They're continuously updating everything, including system libraries. You can easily end up in a situation where getting a security bugfix means you have to update nearly the entire OS thanks to it being built against updated core system libraries.
Like Gentoo it's one of those OSs that is cool for linux nerds and a headache for people who actually need to practice proper systems engineering.
Its a falsehood pushed by old 80's thinking. It sounds nice, in theory.
In practice, what you often get are bugfix patches blindly applied to older codebases, oftentimes by people (distro maintainers) who are not very familiar with the codebase. As long as the patch applies, and it passes various tests.
Remember, most OSS projects - including some critical ones - do not have large teams of devs able to maintain multiple codelines in tandem. Usually, the dev(s) just work on the latest, and pay only cursory attention to applying security bugfixes to older versions.
After all, how is an OSS dev for proj X meant to know (or even give a damn for) which distro arbitrarily decided which older version is somehow the SECURE and BLESSED one.
The dev in question probably moved on from that version months (and in regard to Debian, probably YEARS) ago.
So in theory, what you said sounds right. In practice, no.
Seen it done and participated.
I've also known a couple shops that run Gentoo as their distribution. Usually a central binary package host / build machine which makes it very easy to have a set of staging hosts. Just test package releases like normal before migrating them to prod.
People have used Arch in prod. But personally I'll still use Debian to be on the safe side despite all of the issues that comes with.
[0] https://wiki.archlinux.org/title/System_maintenance#Partial_...
But sure, just yoloing a single package upgrade can break things, obviously.
Fear not. As GKE is running on Container-Optimized OS which is based on Chromium OS which itself is based on Gentoo, you can safely practice proper systems engineering within the container environment :)