 
            Jonathan McDowell wrote:
apt-get --print-uris -y -qq upgrade
Great! Thanks.
I can get the change notes via: aptitude changelog <pkgname> .. for each package, and then presumably just need to "apt-get install" the selected packages. So that's the theory covered...
NB: Since this is primarily for use on internal servers (ie not Internet facing) I plan on using the sudoers file to grant the web user (www-data) passwordless access to apt-get/aptitude. Can anyone give me reasons why that is a bad idea and/or suggest how else to do this?