How would you ensure that third-party software has a mechanism for receiving security updates?

How would you ensure that third-party software has a mechanism for receiving security updates? discuss