Context
For some projects, we need to keep WordPress core on a specific minor branch (e.g., 6.4.x or 6.5.x) for compatibility and controlled rollout reasons.
Problem
Today, the update behavior forces WordPress core to the latest available version (latest major/minor), rather than allowing us to stay within a selected minor branch and only apply patch releases.
Request
Add an option to choose the WordPress core update policy per site (or per group), such as:
• Latest version (current behavior)
• Latest patch of a selected minor branch (e.g., stay on 6.4.x and automatically update to 6.4.4, 6.4.5, etc.)
Expected behavior
• If a site is pinned to 6.4.x, the system auto-updates only within 6.4.*.
• It should not upgrade to 6.5.0+ unless the policy is changed.
• UI should clearly display the chosen policy and the target branch.
Benefit
This enables safer, more controlled core updates for enterprise contexts:
• better compatibility management (plugins/themes),
• staged rollout across fleets,
• reduced risk of unexpected major/minor upgrades.