Security patches need to be entirely separate to performance degradation patches. You should be able to say no thankyou to your vendor gimping your product without them holding the "no security for you" gun to your head.
When you buy a device, security patches for that OS for 5 years should be a requirement for the device being fit for purpose.
For anyone not aware, Apple is extremely hostile to device longevity and 3rd party repair [1]. They have had issues with hinge design in MacBooks as well as the Bendgate crisis for the iPhone 6 series.
They bricked phones when people had other repair shops fix their home buttons (Touch ID sensors).
Apple wants to control everything, sell you a device with a short lifespan, and then force upgrades.