Updating packages is routine, but it helps to know whether a command is only checking for changes or is about to install them. On a DNF-based system, dnf check-update checks for available updates; dnf update and dnf upgrade apply them.
Check before you change anything
To see whether enabled repositories offer newer package versions without installing them, run:
sudo dnf check-update
If updates are available, DNF prints package names and versions. The command commonly exits with status 100 when updates are available, 0 when none are available, and 1 for an error. That means a script should not automatically treat every nonzero result as a failure.
You can also list packages with available updates:
dnf list --updates
These commands help you inspect what is available. They do not apply the updates.
Apply updates with a reviewed transaction
When you are ready to install available updates, run:
sudo dnf upgrade
DNF checks enabled repositories, resolves dependencies, and displays a proposed transaction. Review that summary before confirming. Depending on package versions and dependency requirements, the transaction may update dependencies or remove packages; it is not always limited to a simple replacement of each installed package with a newer version.
On current DNF, dnf update is an alias for dnf upgrade. They perform the same package-upgrade operation, but upgrade is the preferred spelling in current DNF documentation. If you are used to typing update, it remains a valid option on current DNF systems.
The exact commands and behavior can vary across distributions and DNF versions. If you are new to the package manager, this overview of Fedora’s DNF and basic package commands is useful background.
Updating one package
You can name a package to request an update for that package:
sudo dnf upgrade nginx
Replace nginx with the package name you want. DNF may also install or update dependencies to complete the transaction, so check the proposed changes before accepting them. If the named package is not already installed, DNF may offer to install it. Read the summary carefully if your intention is to update an existing package only.
When to use --refresh
DNF caches repository metadata and normally refreshes it according to its expiration rules. If you suspect the cached metadata is stale, add --refresh:
sudo dnf upgrade --refresh
This makes DNF treat the metadata as expired and retrieve fresh repository information before continuing with the package transaction. It does not merely refresh metadata and stop: the upgrade operation still proceeds. Review the proposed changes as usual.
Automatic confirmation and security updates
The -y option automatically confirms prompts:
sudo dnf upgrade -y
This can be appropriate in a managed automation workflow where the transaction is expected. On a production server, skipping confirmation also skips the opportunity to review the changes interactively. Prefer a workflow that accounts for the packages and dependencies DNF plans to change.
Some DNF versions and distributions support requesting updates marked as security-related:
sudo dnf upgrade --security
This depends on the distribution and on security advisory metadata being available from configured repositories. It may also require dependency changes. Do not assume this option finds every security fix: check the guidance for your distribution and review the transaction.
A package update is not a release upgrade
Running dnf update or dnf upgrade updates packages available for your configured system release and repositories. It is not the usual procedure for moving to a new major release of Fedora or another distribution. Release upgrades use distribution-specific workflows, and supported paths and preparation can differ.
Before following release-upgrade instructions, confirm which distribution and version the machine is running. The commands in this guide to checking your Linux version can help you identify it.
A simple workflow
For an interactive update, a practical sequence is:
sudo dnf check-update
sudo dnf upgrade
The first command shows whether updates are available; the second proposes and applies them after you approve the transaction. If the check reports updates, look at the package list, then pay attention to DNF’s final summary before confirming.
The key distinction is straightforward: use check-update to inspect availability, and upgrade (or its current-DNF alias, update) when you are ready to apply package changes. Neither command is a substitute for the separate, distribution-specific process of upgrading the operating system release.
I originally published a more detailed version of this guide on the SSHFlow blog.
I'm also building SSHFlow — an SSH client where every server gets its own workspace for terminals, SFTP, code, and databases.
Top comments (0)