Classify the change
Classify each item as a security fix, bug fix, feature, performance improvement, or behavioral change. A feature unrelated to your use case does not by itself require a production update; assess benefit and risk together.
Check dependencies
Look for changes to the web interface, MQTT topics, HTTP API, Ping Watchdog, scheduling, and external modules. Add fields expected by Home Assistant or custom applications to the test list.
Use a pilot device
Update a non-production device or a low-risk site first. Run I/O scenarios that represent normal load and allow enough observation time, then deploy in stages.
Document the decision
Record the reason for updating, deferring, or skipping, along with test results and approval. For deferred security fixes, define compensating network restrictions and a review date.