We follow the Jenkins LTS branch for the version we run, and we so have to update jenkins itself, or some plugins, when some CVEs, security fixes are announced, and also to comply with some other internal rules for CI/CD platform.
The process is easy for that part:
adhoc-upgrade-jenkins.yml
playbook