Getting your software into the default package managers is not necessarily the best choice for a new and fast-moving project. You'll be stuck answering bug reports for an ancient version and monkey-patching it for the life of the LTS release. It's much more ergonomic, both for maintainers and users, to run your own PPA or repo with the latest version.
If you want stable, you want a non-changing branch with security fixes only. No surprises, no api changes, no config file changes.
And you don't want to be stuck on a non-security fix version. You cannot sit on the same version without tracking security, while you slowly retool and recode for breaking api/behaviour changes.
Debian stable has redis, and others, and will see backported security updates for the life of the support window.
This isn't just about redis. If you're doing this with anything, you must track secuirty updates, must stay up to date, or you are negligent. And tracking changes for infra stuff like redis, and other backend stuff is a waste of resources with typically zero benefit.
I won't touch core daemons like redis, if it isn't distro maintained. I have better things to do. More important things to worry about.
Case in point: there are known vulnerabilities in the version of Redis shipped with Ubuntu 22.04 LTS, which a lot of people would assume is still maintained. But Redis is in universe, so patches are only available for those with an Ubuntu Pro subscription.
Ubuntu throws 90% of its packages in universe and doesn't even bother to pull security fixes from Debian. It's absolutely irresponsible and not comparable to Debian at all.
That sounds like a GitHub Actions problem. GitHub Actions only offers a very limited set of container images, and for Ubuntu they just go with the LTS version that shipped before Valkey even existed.
https://docs.github.com/en/actions/writing-workflows/workflo...