Security Updates

Updates and Unattended Security Patching

On Debian 319 and Ubuntu 225 , security patching is automated by unattended-upgrades, started by apt-daily-upgrade.timer, which Ubuntu enables by default. /etc/apt/apt.conf.d/20auto-upgrades switches it on; 50unattended-upgrades lists the origins it may install from (Unattended-Upgrade::Allowed-Origins), the packages it must skip (Package-Blacklist) and whether it may reboot (Automatic-Reboot, best left "false" on a server you care about).

When unattended upgrades run, and which origins they may useShell
systemctl cat apt-daily-upgrade.timer | grep -E '^(OnCalendar|RandomizedDelaySec)'
sudo unattended-upgrade --dry-run --debug 2>&1 | grep '^Allowed origins' | sed 's/, /\n  /g'
Output
OnCalendar=*-*-* 6:00
RandomizedDelaySec=60m
Allowed origins are: o=Ubuntu,a=resolute
  o=Ubuntu,a=resolute-security
  o=UbuntuESMApps,a=resolute-apps-security
  o=UbuntuESM,a=resolute-infra-security

Upgrades run daily around 06:00, spread over an hour. Only Ubuntu's own origins qualify; the same log marks every repo.mysql.com index "not allowed", so Oracle's MySQL 9.7 524 is never patched automatically.

A patched library does not restart the services using it: php8.5-fpm keeps the old OpenSSL in memory until restarted, which needrestart detects. A kernel upgrade needs a reboot, flagged by /var/run/reboot-required. On RHEL-family systems use dnf-automatic (not run here) with upgrade_type = security and apply_updates = yes in /etc/dnf/automatic.conf.