It would be interesting to hear your thoughts on Security fixes should bypass staging — unbound CVE batch as a case study and how you think nixpkgs itself could improve with lessons you’ve pulled from your product.
I assume your suggestion would be having smaller channels for more focused usecases to ship updates faster?