Thank you Crowdstrike for helping to illustrate that Open Source is not the problem.
@privateger @bagder @jimfuller
if that's true it wasn't a "rollout", or at least not a controlled one. A rollout would be turning off updates after small measured increments and checking that things were still going well before proceeding with the next chunk (increment size doesn't need to be constant—often isn't—but does need to start small).
If you're combating an active 0-day attack you might be justified going full-throttle right off the bat, but do so knowing you're rolling the dice.