This is exactly how it works on Debian. Can recommend.
There is a difference between
- software company decides to release a new version and auto installs it for everyone who has the old version (like Google Chrome)
- software company decides to release a new version. The Debian packaage maintainer checks if the update is fine, is compatible with Debian policies, then includes it in the packages repositories.
In the first, there are no checks. In the second, there are.
Guess what runs my PC. Tech companies just don't understand consent.