Fedora 29 is out today, and it includes a variant image that is Fedora Silverblue -- Fedora Workstation, but with rpm-ostree, immutable root fs, containerized apps, etc. This has many security benefits.
https://silverblue.fedoraproject.org/
Back in 2015, J Rutkowska mentioned:
> 6. Last but not least, having a meaningful intra-VM root-protecting system
> allows to us to finally provide a meaningful defense-in-depth against hypervisor
> exploits (such as the infamous XSA148).
While a Subgraph template for Qubes didn't/hasn't yet become stable, it seems to me that a Fedora Silverblue template could bring some (not all) of the same benefits. It seems like the Silverblue project is heading towards implementing a lot of Subgraph-style features into regular Fedora.
For more info on Silverblue, see:
https://www.projectatomic.io/blog/2018/02/fedora-atomic-workstation/
Jonathan Lebon: Fearless upgrades with Fedora Atomic Workstation (DevConf, Jan 28, 2018)
https://www.youtube.com/watch?v=7c3GdfhWzcc