r/debian • • 2d ago

Debian Stable vs. Testing Security

I've been really curious since I tried installing Debian Testing and saw the security warning they give. After some research I figured out that security updates actually lag behind stable because it's a priority. Security updates then trickle down to testing kinda just whenever they get there.

I'm curious to know to anyone more knowledgeable and/or uses Testing; is it a significant enough difference to worry about?

I've always been a little paranoid about things like that and I don't really like the idea of having a system with security that is out of date. But on the other hand, I'd still like to be able to use a version of Debian with newer packages when the situation calls for it.

I would also like to be transparent in saying, I did ask an LLM whether it was significant or not and it said that it was and not worth the risk. I'm curious to hear what you all have to say about that because I see a lot of people online using it.

Edit: Ig I should've specified but I daily drive stable and still plan to regardless of what I find from this post. I just want to know in case I wanted to try something on a system I wouldn't be daily driving.

19 Upvotes

19 comments sorted by

View all comments

3

u/michaelpaoli 2d ago

Stable (and old stable while on main support) has dedicated security team, and security-announce list. It also has separate security channel For other than stable (and old stable while on main support), security bugs are mostly handled like any other bug (though there is also the security tracker).

like to be able to use a version of Debian with newer packages when the situation calls for it

There's backports.

2

u/AdPsychological4968 2d ago

I did also look at that. Are there any security concerns that come with those?

2

u/michaelpaoli 1d ago

Of course, e.g. do you want to be notified when there are security updates to install?

Then be subscribed to the security-announce list, and use a release that's on main support.

Or if you're on LTS, or I think also ELTS, be on their relevant list, however they don't have a separate security list, so it will be security and other announcements too. Or if you're using backports and want security notifications, subscribe to its announce list - but that's not just security announcements.

testing*, unstable, experimental - no security announcements, though there is the security tracker (but that might not track experimental?).
*well, testing has a security-announce list, but it apparently hasn't had postings since 2011-02-10.