> Debian helpfully "updated" OpenSSL, and thanks to the magic of shared libraries, every program on a Debian system generated weak keys.
I'm going to guess you never checked how many vulnerabilities have been fixed in Linux distributions before a release, or backported to existing releases: hundreds of thousands.
Cherry-picking a single incident (involving a library with a history of vulnerabilities) is hardly meaningful.
> Most stuff "in production" these days is in a container
It's provably not, outside of the SV bubble. The large majority of software in the world is still deployed traditionally.
> So the "quick security updates" doesn't seem to justify the high maintainability cost of shared libraries
A good number of large companies think otherwise. Also, people working in security.
>> I want the binaries properly packaged with metadata, documentation, manpages to keep the host secure and tidy.
> You've just invented containers.
No, these are OS packages and predate containers by many decades. This is getting silly.