@bmeeks Patching was never easy to begin with.
What I'm saying is that a package can be updated without releasing any interim pf release, so it needs less regression testing, than a full point release
Maniplulationg text (php) and configuration files is different from changing binary files.
What Im trying to say is that ce version isn't something left to its (security) fate, only to be fixed if and when the sun is shining.