

Unattended-upgrade does security-only patching once every 4 hours (in rough sync with my local mirror)
Full upgrades are done weekly, accompanied by a reboot
I find that the split between security patching and feature/bug patching maintains a healthy balance knowing when something is likely to break but never being behind on the latest cve.

It’s much simpler than that actually. Nvidia makes a lot of money in feature licensing, particularly GRID/vgpu. If they fully open-sourced the driver they would have no method of enforcing license restrictions.