Software like this shouldn't need to be constantly updated. Users should only update full node software when they understand and trust the changes made from their current version. Of course tons of people can't be bothered or don't know how to evaluate the security of their software. Hopefully those people are good judges of character.
I agree, updating full node software is a problem for normal users. However, if we can develop a core set of first layer software that's stable enough, it could go many years without needing an update. And individual users may only need to update some of those times. So at least the burden could be arbitrarily low. But we certainly shouldn't have set-and-forget auto updating software - that would be a huge security flaw.