Qubes OS gives him high security with relative ease.
Fedora Silverblue with auto update and Flatseal tightened apps is a nice middle ground.
RHEL minimises supply chain attack risk and provides features like kernel hot patching. He can use free developer subscriptions. Also try SUSE.
Security wise Chromium is a bit better than Firefox. Try to seal it up with SELinux. Red Hat only supports Firefox however.
SecureBlue can be used as a reference, but it’s still downstream so personally I’d avoid using it in case of supply chain attacks unless securing Silverblue is too much of a hassle.
Keep in mind that Flatpak sandbox interferes with browser sandboxes.
Qubes OS gives him high security with relative ease.
Fedora Silverblue with auto update and Flatseal tightened apps is a nice middle ground.
RHEL minimises supply chain attack risk and provides features like kernel hot patching. He can use free developer subscriptions. Also try SUSE.
Security wise Chromium is a bit better than Firefox. Try to seal it up with SELinux. Red Hat only supports Firefox however.
SecureBlue can be used as a reference, but it’s still downstream so personally I’d avoid using it in case of supply chain attacks unless securing Silverblue is too much of a hassle.
Keep in mind that Flatpak sandbox interferes with browser sandboxes.