> so it is download source tar balls and build your own for ultimate stability?

Not to this extend, installing things from packages are okay.

> what do you do when a vulnerability has been posted and impacts you?

There were no substantial vulnerabilities for those packages in years, if my memory doesn't fail me. But even is something comes up, there are additional measures like fail2ban on open ports.