### Summary of the new feature / enhancement There should be an agreed upon practice to tag package releases that are security updates with a `SecurityPatch` tag as well as with any associated CVEs Then we should add tag support for Update so you can update all packages with a security patch ### Proposed technical implementation details (optional) _No response_