- Does Silverblue being immutable has an effect on security, or is it more about stability and reliability?
It should also be more secure. The fact that your install is the same as thousands of others, including the devs', and that updates get patched as a whole, makes it more secure due to the reproducibility you mentioned.
If the devs notice a flaw, it will also be on every other install and fixed immediately.
In theory, malicious actors also can't modify the (live) system, but I can't make a statement about that.
You can also take a look at SecureBlue if security is very important to you.
Updates get installed automatically and staged, so you can just boot into a fresh and updated image every day when shutting off the PC before bed without even noticing :)
- Is it possible to have Nvidia drivers with Secure Boot on Silverblue, and how?
Go to universal-blue.org and select your wanted image there. They have a Nvidia-image for every variant, where the drivers are already baked into the base image.
They support Secure Boot, and if the driver breaks, which it shouldn't, because then thousands others would do that too, you can just select yesterday's image and don't have to worry about fixing something. Your OS will always boot and be usable!
Take a look at my post for further information: https://feddit.de/post/8234416