Coming from Gentoo -> Debian I am to trying to understand the way CentOS works. In Debian very little happens in stable releases and you use apt-get update to apply security updates and apt-get dist-upgrade for a major upgrade. In CentOS there is an yum-security plugin which allows you to install security updates only. If I understand correctly the preferred way though is to do at least an yum upgrade every 6 months in order to upgrade to a point release.