IMO the updater needs a blacklist to mark packages for no further upgrading them. as Alex resumed "allowing to pin packages to a version and stop them from upgrading."
That would either result in upgrades getting blocked because of unresolvable dependencies or you not getting security updates or both. I don't see that as a feature a high level tool like discover should expose. It has unique foot-shooting potential.