If you are running things inside of containers you aren’t helping yourself by disabling unprivileged namespaces, you are actually just running more things as root. Inside the containers they generally block namespaces anyway.
TBH I’ve never heard anything positive about most of what hardened does.
Nobody else has this hybrid model. RHEL is a paid distro in general. Most others are just free entirely. They all patch CVEs when they can. Ubuntu doesn’t write all of their patches or anything.
Anything less than mainline support is ewaste imo. Look how terrible the pi graphics support used to be but now thanks to excellent upstream kernel/Mesa drivers it’s great and will continue to work/improve for the foreseeable future.
The gap between “nothing has been done for this task” and “multiple developers have written, reviewed, and discussed patches for this” is immense and positive.
The comment on there is odd, I’m not even sure what that issue is referring to. Not much exciting happened in that release for new features but there were subsandbox security fixes github.com/flatpak/flatpak/…/1.10.8...1.12.0