Every time a new firmware update drops for a hardware wallet, I find myself second-guessing whether to install it or just leave the device alone.
Which hardware wallet do you have?
If the firmware doesn't contain fixes for critical errors, then I suppose installing the new firmware can be postponed (for a while).
On one hand, keeping an air-gapped device on an older, stable version that already does basic PSBT signing feels like the safest route.
The Coldcard incident demonstrated that not all older firmware versions are secure (they may contain legacy vulnerabilities).
There is no risk of a bad release bricking the device, unexpected code changes, or unwanted features being introduced.
It seems you’ve described all the paranoid fears that owners of hardware wallets have regarding the new firmware.

If the device has never touched the internet and only signs raw transactions offline, it feels like "if it isn't broken, don't touch it."
Let’s revisit the Coldcard story. The devices from which funds were stolen could also have gone years without connecting to the internet (the vulnerability stemmed from overly simple generation of the seed phrase). So, this is (don't touch HW) far from a 100% guarantee of security.
On the other hand, security advisories and bug disclosures pop up occasionally, and ignoring patches could theoretically leave known vulnerabilities open to physical side-channel attacks or parsing bugs.
Therefore, I believe one should install updates rather than ignore them - much like anti-vaxxers refuse vaccinations (only to subsequently fall ill).
For those of you holding long term in cold storage, what is your actual routine here? Do you flash updates as soon as they roll out, wait a few weeks or months to see if other users report issues, or simply keep your signing device on its factory firmware until a transaction literally fails to build?
Well, relying solely on the factory firmware doesn't seem entirely sensible to me (for the latest update version may differ significantly from the factory version, especially if the hardware wallet model is no longer new). Besides, updated firmware often includes new features. That’s why I prefer to update the HW device, though I do so with a bit of a delay. I don't stick to a strict schedule for updates - usually, it’s a matter of days or weeks (though the delay can be longer if I haven't used the HW device for a while). If there isn't a lot of "noise" about issues following the update's release, I go ahead and install it.
I think the "Hardware wallets" section would be more suitable for this topic.