Yes, Ubuntu is withholding security patches for some software
flu0r1ne.net
flu0r1ne.net
Ubuntu Pro Shenanigans - https://news.ycombinator.com/item?id=38254040 - Nov 2023 (92 comments)
PPAs are built against Ubuntu packages as dependencies - which usually but not always match Debian ones. Easy way to get subtly broken programs
These days you can get close with github-actions style pieplines and releases, but the PPA system has always been a more complete platform in terms of dependency management.
You can get close with some debian tooling (im a fan of sbuild), but it's some overhead to deal with.
Also Debian is always much further behind than Ubuntu on new packages.
When I install an LTS version with a Universe package like ffmpeg, does everything continue getting security patches for the full five-year LTS life?
Or do I now need Ubuntu Pro to get the full five years?
I've been tempted to go back to Arch and I think this can be a good motivator.
Honest question, since the arch wiki seems surprisingly spotty on this: Which arch repos are covered by their security team? Just core? Or also extra? More than that? AUR surely not, right?
Happened to me.
At least, in Debian, most of the packages I use on my server are from their main repos. Occasionally there are a few from other sources but by the time a new Debian patch is released, those other packages are also updated.
For servers, CentOS is reliable as fuck.
IBM isn't exactly the most trustworthy steward.
now we have 'rocky linux' taking the place of old downstream centos as 1:1 bug-for-bug rhel compatible (against ibm's wishes)
and 'almalinux' building a stable release on top of centos stream (ibm seems to be ok with)