@harald-somnes-hanssen_2204 that's... a lot of vulnerabilities 
I did just want to confirm this bit...
Manually by version, where the version is either removed entirely or unlisted .. very ineffective.
Are you referring to deleting/removing vulnerabilities, or the packages themselves? Are you using "retention rules" to clean-up the old chocolatey packages?
Basically the feature idea I'm thinking essentially a checkbox on the Retention Rules, where it deletes the vulnerabilities when the package is deleted, if no other packages are using it. That seems like the easiest and most explicit way to manage going forward 

