Skip to content

SecurityUpdates

Automatic security updates on Linux, Windows and macOS servers

Keep servers patched without daily work: configure unattended-upgrades on Ubuntu and Debian, dnf-automatic, Windows Update on Windows Server and macOS updates.

  • Beginner
  • 15 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows Server 2022, Windows Server 2025, macOS Tahoe 26

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Before you start
  2. Ubuntu and Debian: unattended-upgrades
  3. Install and enable
  4. Choose what is updated
  5. Reboot automatically (optional)
  6. Check whether a restart is needed
  7. Read the log
  8. AlmaLinux and Rocky Linux: dnf-automatic
  9. Windows Server
  10. macOS servers
  11. Updates the package manager does not cover
  12. Troubleshooting
  13. Next steps

Most successful attacks use flaws that were fixed months ago. Automatic security updates close that window without daily work. This guide configures them on Ubuntu and Debian, RHEL-family systems, Windows Server and macOS, and shows you how to handle reboots.

Before you start

  • Have a backup or, where your plan offers it, a snapshot. Windows VPS plans include free snapshots.
  • Decide when the server may restart. A quiet hour at night suits most websites.

Ubuntu and Debian: unattended-upgrades

Install and enable

Ubuntu installs the package by default; on Debian install it. Then enable the periodic run:

Bash
sudo apt install unattended-upgrades apt-listchanges
sudo dpkg-reconfigure -plow unattended-upgrades

Answer Yes. This writes /etc/apt/apt.conf.d/20auto-upgrades:

Text
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";

Verify: a dry run shows what would be installed and that the configuration works:

Bash
sudo unattended-upgrade --dry-run --debug

Choose what is updated

/etc/apt/apt.conf.d/50unattended-upgrades lists the allowed origins. By default only security updates are installed, which is the safe choice. To keep a package from being updated automatically, add it to the blacklist section:

Text
Unattended-Upgrade::Package-Blacklist {
    "mariadb-server";
};

Reboot automatically (optional)

In the same file, allow reboots when an update needs one, at a fixed time:

Text
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:30";

Leave automatic reboots off on servers where a restart needs supervision, and reboot during a maintenance window instead.

Check whether a restart is needed

Bash
ls /var/run/reboot-required
sudo needrestart

On Ubuntu the file /var/run/reboot-required exists when a reboot is pending. needrestart (installed by default on Ubuntu; sudo apt install needrestart on Debian) lists services still running old libraries and whether the kernel is outdated.

Read the log

Bash
sudo tail -n 50 /var/log/unattended-upgrades/unattended-upgrades.log

AlmaLinux and Rocky Linux: dnf-automatic

Bash
sudo dnf install dnf-automatic

In /etc/dnf/automatic.conf, set upgrade_type = security and apply_updates = yes, then enable the timer:

Bash
sudo systemctl enable --now dnf-automatic.timer

Verify: systemctl list-timers dnf-automatic.timer shows the next run.

Windows Server

On Windows Server with Desktop Experience, open Settings › Windows Update to check for updates and see the history; Advanced options sets active hours. On any installation you can use SConfig: open PowerShell as administrator, run SConfig, choose option 5 (Update setting) and select A for automatic: updates are then installed every day at 3:00 AM server time. Option 6 installs updates right away.

Restart after updates at a time you choose. Take a snapshot before large cumulative updates on a Windows VPS.

macOS servers

On a macOS VPS or VDS, open System Settings › General › Software Update and use the info button next to Automatic updates to choose what is downloaded and installed. On a build server, consider installing macOS updates by hand: a new macOS version can require a newer Xcode. Over SSH:

Bash
softwareupdate --list
sudo softwareupdate --install --all --restart

Updates the package manager does not cover

Automatic system updates do not update:

  • applications you installed by hand (a CMS, its plugins and themes, downloaded binaries);
  • container images, which you rebuild or pull again;
  • language packages installed with pip, npm or composer.

Update these with their own tools and subscribe to their security announcements.

Troubleshooting

Updates do not run. Check the timers: systemctl list-timers apt-daily.timer apt-daily-upgrade.timer. Both should show a next run.

apt reports that dpkg was interrupted. An update was running when the server rebooted. Run sudo dpkg --configure -a to finish any interrupted installation.

A package is held back. It needs new dependencies; install it during a maintenance window with sudo apt full-upgrade after reading what changes.

Next steps

Frequently asked questions

Can automatic updates break my server?

Security updates in stable releases change as little as possible, so breakage is rare. The risk of running unpatched software is far higher. Keep backups or snapshots and review the update log after larger changes.

Do I still need to reboot?

Yes, for kernel and some library updates. Either allow automatic reboots at a quiet time or plan a regular maintenance window, for example once a month.

Are all updates installed automatically?

By default unattended-upgrades installs security updates only. You can add other update sources, but feature updates are better installed by hand after reading the changes.

How do I know what was updated?

Read /var/log/unattended-upgrades/unattended-upgrades.log on Ubuntu and Debian, or the update history in Windows Update. Mail notifications can be enabled as well.

What about software outside the package manager?

Applications installed by hand, such as a CMS, its plugins or a downloaded binary, are not updated by these tools. Update them with their own mechanism and subscribe to their security announcements.

Sources

Wachtwoord genereren

Please confirm