On Debian 319 and Ubuntu 225 , security patching is automated by unattended-upgrades, started by apt-daily-upgrade.timer, which Ubuntu enables by default. /etc/apt/apt.conf.d/20auto-upgrades switches it on; 50unattended-upgrades lists the origins it may install from (Unattended-Upgrade::Allowed-Origins), the packages it must skip (Package-Blacklist) and whether it may reboot (Automatic-Reboot, best left "false" on a server you care about).
systemctl cat apt-daily-upgrade.timer | grep -E '^(OnCalendar|RandomizedDelaySec)'
sudo unattended-upgrade --dry-run --debug 2>&1 | grep '^Allowed origins' | sed 's/, /\n /g'OnCalendar=*-*-* 6:00 RandomizedDelaySec=60m Allowed origins are: o=Ubuntu,a=resolute o=Ubuntu,a=resolute-security o=UbuntuESMApps,a=resolute-apps-security o=UbuntuESM,a=resolute-infra-security
Upgrades run daily around 06:00, spread over an hour. Only Ubuntu's own origins qualify; the same log marks every repo.mysql.com index "not allowed", so Oracle's MySQL 9.7 524 is never patched automatically.
A patched library does not restart the services using it: php8.5-fpm keeps the old OpenSSL in memory until restarted, which needrestart detects. A kernel upgrade needs a reboot, flagged by /var/run/reboot-required. On RHEL-family systems use dnf-automatic (not run here) with upgrade_type = security and apply_updates = yes in /etc/dnf/automatic.conf.