

Just mount /home and /var to an SSD, tempFS(If you dont care about your data), or network drive and this is a perfect purpose for USB booting.
Saves your hard drives from all the bootloader stuff, and should be faster than a spinning disk if the drive is 3.0.
Id even mount the USB as read only to ensure it isnt damaged, and use any ISO generator to manage updates from another device (Like create a new flash, shutdown this PC, plug in the new flash - bam update complete)





Oh god yeah, its just filtering through the slop that actually matters.
But like the XZ trojan that was only affecting Debian installs, each distro needs to individually have competent maintainers to ensure their store is safe.
If for exapmle I set a couple ‘bugfixes’ in the guix package file for emacs, I could reasonably infect a number of systems if a lazy maintainer just approved the request. (Or other attacks without even involving guix if I notied a bug in a package spelling and typo squatted it, or stole signing keys and pushed updates to the repo myself).
None of these would change anything to other distros maintainers, but because this distros AI maintainer could risk a large number of users devices.