Keep your bits under the radar!

Security Updates


When you installing new Ubuntu Server OS, always enable - “Install security updates automatically”. But, if you don’t know what is made by your system administrator you can make by your own.

 To configure manually for install software updates and security patches automatically, first we need to install unattended-upgradespackage. To do so, run:

Command:

sudo apt install unattended-upgrades

and make the changes that fits to your needs.

 // Automatically upgrade packages from these (origin:archive) pairs
Unattended-Upgrade::Allowed-Origins {
"${distro_id}:${distro_codename}";
"${distro_id}:${distro_codename}-security";
// "${distro_id}:${distro_codename}-updates";
// "${distro_id}:${distro_codename}-proposed";
// "${distro_id}:${distro_codename}-backports";
};

As you see in the above configuration, you should configured packages from security APT source to upgrade automatically. You can uncomment the other lines if you want to configure automatic updates from other APT sources such as updates, proposed, and backports, just uncomment the respective lines. Save and exit the file.

You can also blacklist some packages from being automatically updated by adding them in the blacklist like below. Anything that comes under this list will not be updated automatically.

// List of packages to not update (regexp are supported)
Unattended-Upgrade::Package-Blacklist {
// "vim";
// "libc6";
// "libc6-dev";
// "libc6-i686";
};

As per the above configuration, the packages called vim, libc6, libc6-dev, libc6-i686 will not be automatically updated. We have configured automatic updates.

 Next, we need enable automatic updates. In: edit /etc/apt/apt.conf.d/10periodic file:

Command:

sudo nano /etc/apt/apt.conf.d/10periodic

 Make the changes accordingly.

APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Download-Upgradeable-Packages "1";
APT::Periodic::AutocleanInterval "7";

 As per the above configuration, the software sources will updated, the list of available updates will automatically downloaded and installed everyday. And then, the local cache folder will be cleared every week.

Enjoy.