Could you elaborate on the htmx security holes? I only know about xss attacks, and for those it's trivial to sanitize in the backend.
I too gravitate towards just templating for static or simple interactivity, but for pages that need SEO and interactivity I'm still wondering what's a good solution that doesn't involve SSR and a js framework. For a recent project I had I generated the html in php and sent a lot of pure js for dom manipulation
Just to provide counter examples, in arch I can't use the native steam package and play games with proton. It just doesn't work. I think proton expects some ubuntu libraries or something (found something like that while spending 5 hours debugging nfs heat). And even if I manage to fix it, next time I update the system it'll be broken again.
I use flatpak, and everything just works.
However, in arch if something is in the official repo or the AUR i prefer those.
In ubuntu I installed krita and gmic, but it doesn't work. For some reason krita doesn't find the gmic executable. Instead of debugging krita and gmic for hours I just installed the flatpak version, and it just works.
And yeah, app startup went from 5 to 7-10 seconds in krita, and from 1 to 2-3 seconds in firefox. It's not snap, it's 2023, we have SSDs.