I get them from the Apple's "Security Announce" email list.
https://lists.apple.com/mailman/listinfo/security-announce
Doesn't always have all of the app updates, but OS and major updates come out pretty promptly.
There's also the US-Cert alerts, which usually come in within an hour or two after the Apple email for me.
Full list of Apple's email lists at: https://lists.apple.com/mailman/listinfo/
@stevesmith Another useful source of OS and security update info is running your own NetSUS (or just a Reposado instance) to pull the updates list from Apple's Software Update Service servers. It's not clear that SUS will still be used High Sierra, but at least through Sierra all the OS and security updates (including Gatekeeper Configuration Data) are included. Note that if you do go with a NetSUS, as of version 4.1.0 the version of Reposado included does not include the changes from the Reposado GitHub repo for Sierra/10.12 updates, so you'll have to manually make those changes on your NetSUS.
I use IFTTT to send me an email/SMS whenever there is a new update to Apples official RSS feeds regarding security updates and downloads. Found this to work best so far over the past year or so and super simple to setup with IFTTT (https://ifttt.com/discover)...
http://rss.support.apple.com/?service=DOWNLOADS
https://rss.support.apple.com/appleremotedesktop