The ultimate reason is that security bug fixes are an absolute requirement, and unless someone is paying, most OSS providers aren't interested in doing multiple sets of bug fixes. That is the promise- and entire business model, honestly, of Red Hat, they will backport security bugfixes to your stable version.
Otherwise, since we rely so much on free software development, it kinda has to be that way.
Comments
The ultimate reason is that security bug fixes are an absolute requirement, and unless someone is paying, most OSS providers aren't interested in doing multiple sets of bug fixes. That is the promise- and entire business model, honestly, of Red Hat, they will backport security bugfixes to your stable version.
Otherwise, since we rely so much on free software development, it kinda has to be that way.