How do you handle downtime due to project/package/os upgrades?
Additionally, not every update needs to be applied, you need to understand your threat model and only apply updates when they actually patch something that would affect you - this cuts down on the actual number of updates that you need.
Same security industry convinces you to upgrade every 15 seconds and then sells you solutions for when those upgrades fuck you over.