I get security bug fixes on a almost daily basis from a known distro. An application not from a distro I would download source, eyeball before building.