upgrade only vulnerable packages with apt

Since I’m using Debian Sid (unstable), every now and then, some stuff gets broken. I have no problem with that — using Sid, it’s expected behaviour. However, sometimes I *really* don’t have time for a broken setup, so I quit upgrading for a week or so.

The problem will be clear already to most: what with security-wise vulnerabe packages? What if that SSH version I’m not installing in fact contains a fix for a remote root exploit I’m not aware of?

