I use secureblue, because it offers the (AFAIK unique) intersection between:
- a security-first^[To be precise, it's actually Linux-first and security-second. For an actual security-first approach, consider taking a look at Sculpt OS employed with the seL4 kernel run on ARM or 64-bit RISC-V.] approach while being fit for general computing
- a first-class citizen of the ~~'immutable'~~ reprovisionable, anti-hysteresis paradigm
- a well-maintained project with many active contributors that exhibit a proactive stance when it comes to implementing (security) improvements
Because, and I quote:
Thankfully, there's a mailing list that covers issues like these. Heck, OP's PSA was probably originally propagated from there.