DO "just update"
AC says "You don't just update server software in a production environment because a new version came along."
I know that "received wisdom" is to look at problems you have, only update if the update address an issue you've seen, or if you believe yourself to be vulnerable to a security issue the update corrects. Other than that, leave "production" systems alone.
I don't run like that. Never will. Argue with me if you like, but I've been on exim 4.71 for ages, went to 4.72 soon after it came out. So, with a smug grin, I know I'm in the clear.
My strategy is - ALWAYS update. Life's too short to plough through every issue, see if a particular update addresses it. And are you really, really, really sure every change has been logged in sufficient detail for you to know exactly what issues are corrected ??
Keep the ability to roll back if anything breaks, but keep updated. It's not the ass-covering approach, but it is the professional approach.
YMMV, and all that stuff.