>Newer is always better?
I did not say that it is _always_ better. I said that someone should read the changelog for every dependencies in order to make a decision.
Dependencies are not usually related only to the package installed. In my opinion yes, it is best to try to understand the fixes from the new releases and apply those on working servers. Why should someone wait for HP to release a new depot for the same piece of software that was changed a few days ago?
From November 2009 until today there are 6 months. Read the changelog/docs for openssl about security issues that were fixed in this period.
Horia.
Best regards from Romania,
Horia.