Earlier quoted context omitted.
Unfortunately the software deployed on top of them will. So you either: 1) postpone all your updates for years until a bad CVE hits and you need to update or some application goes end of life and you’re screwed because updating becomes a massive exercise 2) do regular updates and patches to the entire stack, including Linux, in which case, you’re in the same position you were before with running on the stack rot trea…
My rationale for staying up to date aggressively is that it minimizes integration work. Basically integration work multiplies, it doesn't just accumulate. So the further you fall behind the more that can break when you finally do upgrade. And you create needlessly more work related to testing and fixing all that. Upgrading a system that was fully up to date until a few days/weeks ago is generally easy. There's only s…
If business understands that you need time to work on these things :’)