Securing the system by keeping it up-to-date

Petr Bokoc, Mirek Jahoda, Gregory Lee Bartholomew Versão unspecified Last review: 2023-12-23

Why it is important to keep your system up-to-date

This section briefly explains the importance of updating your system on a regular basis.

All software contains bugs. Often, these bugs can result in a vulnerability that can expose your system to malicious users. Packages that have not been updated are a common cause of computer intrusions. Install security patches promptly to end discovered vulnerabilities quickly, so attackers cannot exploit them.

Manual updating using GUI

The following steps describe how to manually download and install new updates by using GUI.

Procedure

  1. Hover the cursor over the upper-left corner of the screen and type "Software" and select the Software application to open it.

  2. Click the Updates button to view the available updates.

  3. Click the Download button to download new updates.

  4. After the updates are downloaded click the Restart & Update button. Your system will restart to perform the upgrade.

Updating by using the Software application

Manual updating using CLI

The following steps describe how to manually download and install new updates by using the DNF package manager.

Fedora recommends applying updates offline: packages are downloaded while the system is running normally, then applied during a reboot. This avoids conflicts caused by updating libraries or services that are actively in use.

Procedure

  1. Download available updates:

    $ sudo dnf offline-upgrade download

    Confirm to download the available packages.

  2. Reboot to apply the updates:

    $ sudo dnf offline-upgrade reboot

    The system reboots, applies the downloaded updates, then starts normally.

  3. Optionally, use the rpmconf command to merge any configuration file changes introduced by the package updates:

    $ sudo rpmconf -a

    To use the advanced merge option, set the MERGE environment variable to an editor capable of performing that function (e.g., export MERGE="vimdiff"). See the man page for details.

    If you install the rpmconf DNF plugin, rpmconf runs automatically at the end of each upgrade:

    $ sudo dnf install python3-dnf-plugin-rpmconf

Additional Resources

  • The dnf(8) manual page

  • The dnf-offline-upgrade(8) manual page

  • The rpmconf(8) manual page

Setting automatic updates

The dnf-automatic package provides a systemd timer that can automatically download, install, or alert you about available updates. Whether the timer downloads only, installs, or just notifies the options in the /etc/dnf/automatic.conf configuration file.

For full setup instructions, see Automatic Updates.