MYTHOSAI

Linux security / PRACTICAL GUIDE

Check Ubuntu automatic security updates

Inspect unattended-upgrades, test its decision process and verify that important updates complete.

Before you start

Supported Ubuntu with sudo; repositories and maintenance windows under your control.

Package installed does not mean policy verified

Ubuntu can use unattended-upgrades to apply selected package updates automatically. The configured origins, timers, exclusions and reboot settings determine what really happens. A running service alone does not prove yesterday's security update was installed.

Inspect the current setup

bash
dpkg-query -W unattended-upgrades
systemctl list-timers 'apt-daily*'
apt-config dump | sed -n '/APT::Periodic/p'

If the package is missing and you want this feature:

bash
sudo apt update
sudo apt install unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades

Read the configuration prompt. Do not assume this enables all third-party repositories or a full release upgrade.

Review the actual policy

Inspect /etc/apt/apt.conf.d/20auto-upgrades and the unattended-upgrades configuration, commonly 50unattended-upgrades plus any local overrides. Check permitted package origins, exclusions and whether automatic reboot is enabled. A server handling backup or monitoring traffic needs deliberate restart scheduling.

Do not copy a distribution codename from another release. Repository patterns must match the server's own release and intended sources.

Test without applying updates

bash
sudo unattended-upgrade --dry-run --debug

Read what the tool would select and why it skips packages. The dry run does not prove an update was installed. It can generate detailed logs, so keep them private if repository URLs or system details are sensitive.

Verify a completed update

Review /var/log/unattended-upgrades/ and package history. Confirm the relevant package version changed. Check failed services after maintenance and whether a reboot is required. A patched package on disk may still have an old process running until the appropriate restart occurs.

Common problems

A package-manager lock can mean another legitimate update is already running; do not delete lock files while the process is active. Third-party repositories may be excluded intentionally. Held packages need an owner and a plan, not indefinite silence.

Free scope and operational limits

This guide uses normal Ubuntu repository capabilities and does not require a paid updater. Expanded support products have separate eligibility and pricing and are not assumed. Automatic updates reduce manual effort, but you still need monitoring, sufficient disk space, application checks and a tested recovery route.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.