I was wondering this for quite some time. For example in Debian, I'm using FOSS-only software but I make an exception for "intel-microcode". This of course leads to enabling whole non-free and contrib repos, although you can at least prevent accidental install of any further non-free software by apt-pinning.
So arguments for installing ucode updates:
- proprietary microcode is already baked into your CPU anyway
- they most likely provide more security by patching vulnerabilities
- you are no longer at mercy of mainboard manufacturer's to provide you with ucode updates, which are usually delayed a lot or straight up not supported on older hardware
- they don't run in kernel space, they are only sent to the CPU itself, so you could argue they don't blob your system
And the downsides:
- it goes against the FOSS principles to rely on proprietary updates
- you have to trust a corporation that it really fixes something and not introduces even more vulnerabilities or backdoors
- most of the time, mitigations can be applied the FOSS way by recompiling the kernel or applications
- it messes with your free-only repository setup
Trisquel, for example, has some discussions on their forums about this very issue and most users seem happy that ucode updates are NOT included there.
So after all, it all comes down to preference? What do you think?
SOCIAL SHARE CARD GENERATOR