# How to Automate Security Updates and Alerts in Linux

> Automate Linux security updates and alerts with unattended-upgrades apt-listchanges and apticron. Achieve hands-free patching and stay informed about system changes effortlessly.

- Repository: [IMTheNachoMan/How-To-Secure-A-Linux-Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server)
- Tags: how-to-guide
- Published: 2026-05-14

---

**You can automate critical security patching on Debian-based systems by combining `unattended-upgrades` for silent installation, `apt-listchanges` for reviewing changelogs, and `apticron` for email notifications, creating a hands-free update pipeline that keeps administrators informed.**

Keeping a server patched is the cornerstone of any hardening strategy. This guide explains how to automate security updates and alerts in Linux using the Debian-based toolchain recommended in the `imthenachoman/How-To-Secure-A-Linux-Server` repository. By implementing these three integrated tools, you ensure critical vulnerabilities are patched automatically while maintaining visibility into pending changes.

## The Three-Pillar Automation Architecture

The solution relies on three specialized packages working in concert:

- **`unattended-upgrades`**: Handles automatic installation of security updates by running from the system's regular APT cron schedule and matching packages against a defined *Origins-Pattern* list.
- **`apt-listchanges`**: Parses package changelogs before upgrades occur, allowing you to review exactly what will change before it happens.
- **`apticron`**: Scans for downloadable but not-yet-installed packages and sends concise email alerts to administrators.

According to the source guide, this architecture provides automatic unattended installation of critical security patches while delivering email alerts for non-critical pending updates. This allows you to schedule manual upgrades at convenient times while remaining protected against emergent threats.

## Installing the Automation Toolkit

Begin by installing the three helper packages:

```bash
sudo apt update && sudo apt install -y \
    unattended-upgrades \
    apt-listchanges \
    apticron

```

## Configuring Automatic Security Updates

The `unattended-upgrades` package reads configuration from `/etc/apt/apt.conf.d/`, but the default files may be overwritten during package updates. The guide recommends creating a custom persistent configuration file.

### Creating a Persistent Configuration File

Create `/etc/apt/apt.conf.d/51myunattended-upgrades` to store your settings. This file takes precedence over the default `50unattended-upgrades` and survives package upgrades:

```bash
sudo tee /etc/apt/apt.conf.d/51myunattended-upgrades > /dev/null <<'EOF'
// Enable the periodic APT actions
APT::Periodic::Enable "1";
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Download-Upgradeable-Packages "1";
APT::Periodic::AutocleanInterval "7";

// Run unattended‑upgrade automatically
APT::Periodic::Unattended-Upgrade "1";

// Only upgrade packages from these origins (security & stable)
Unattended-Upgrade::Origins-Pattern {
    "o=Debian,a=stable";
    "o=Debian,a=stable-updates";
    "origin=Debian,codename=${distro_codename},label=Debian-Security";
};

// Do not blacklist any packages (feel free to add your own)
Unattended-Upgrade::Package-Blacklist {};

// If dpkg is in an inconsistent state, fix it automatically
Unattended-Upgrade::AutoFixInterruptedDpkg "true";

// Do NOT wait for shutdown to apply upgrades (safer on always‑on servers)
Unattended-Upgrade::InstallOnShutdown "false";

// Send an e‑mail after each run (to root by default)
Unattended-Upgrade::Mail "root";
Unattended-Upgrade::MailOnlyOnError "false";

// Clean up unused dependencies after upgrades
Unattended-Upgrade::Remove-Unused-Dependencies "true";
EOF

```

### Understanding Origins-Patterns

The `Unattended-Upgrade::Origins-Pattern` block defines which repositories qualify for automatic installation. The configuration above specifically targets:

- **Debian stable** and **stable-updates** archives
- **Debian-Security** labeled packages matching your distribution codename

This pattern ensures only security-relevant updates from trusted origins are applied automatically, preventing potentially breaking changes from untested sources.

## Setting Up Email Alerts and Changelog Tracking

With the base configuration in place, configure the notification components.

### Configuring apt-listchanges

Run the reconfiguration tool to set display preferences:

```bash
sudo dpkg-reconfigure apt-listchanges

```

Select "Yes" for displaying changes and choose your preferred notification method when prompted. This tool reads settings from [`/etc/apt/listchanges.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/apt/listchanges.conf) and shows changelogs before packages install.

### Configuring apticron

Edit [`/etc/apticron/apticron.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/apticron/apticron.conf) to specify the email recipient for pending update alerts:

```bash
sudo sed -i 's/^EMAIL=root@localhost$/EMAIL=root/' /etc/apticron/apticron.conf

```

This ensures scans for downloadable-but-not-installed packages trigger email summaries to the correct address.

## Verifying Your Email Delivery

Before relying on automated alerts, verify the mail transport agent functions correctly:

```bash
sudo /usr/sbin/sendmail -t <<EOF
To: root
Subject: Test email from unattended‑upgrade setup

If you receive this, the e‑mail path works.
EOF

```

Check the root mailbox or your configured forwarding address to confirm delivery. Without a working MTA (such as Postfix or Exim4), `unattended-upgrades` and `apticron` cannot send notifications.

## Summary

- **`unattended-upgrades`** provides automatic installation of security patches by matching packages against specific *Origins-Patterns* in `/etc/apt/apt.conf.d/51myunattended-upgrades`.
- **`apt-listchanges`** displays package changelogs before installation, allowing review of potentially disruptive changes via [`/etc/apt/listchanges.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/apt/listchanges.conf).
- **`apticron`** monitors for pending updates and emails alerts configured in [`/etc/apticron/apticron.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/apticron/apticron.conf).
- Creating a custom configuration file in `/etc/apt/apt.conf.d/51myunattended-upgrades` ensures settings persist across package updates.
- Email functionality requires a working MTA; always test with `/usr/sbin/sendmail` before relying on alerts.

## Frequently Asked Questions

### What is the difference between unattended-upgrades and apticron?

`unattended-upgrades` actually installs security patches automatically without human intervention, while `apticron` only monitors and notifies administrators about available updates without installing them. Together they provide a complete automation pipeline: one handles critical patches silently, the other keeps you informed of pending maintenance.

### Why create a file named 51myunattended-upgrades instead of editing 50unattended-upgrades?

Files in `/etc/apt/apt.conf.d/` are processed in lexical order, so `51myunattended-upgrades` loads after `50unattended-upgrades` and overrides conflicting settings. More importantly, the default `50unattended-upgrades` may be overwritten during package updates, whereas your custom `51myunattended-upgrades` survives upgrades and preserves your specific security policies.

### How do I limit automatic updates to security patches only?

Configure the `Unattended-Upgrade::Origins-Pattern` block in your configuration file to match only the security repository, specifically using `"origin=Debian,codename=${distro_codename},label=Debian-Security"`. Remove or comment out patterns matching stable-updates or other archives if you want strictly security-related automatic installations.

### Will automatic updates interrupt running services?

By setting `Unattended-Upgrade::InstallOnShutdown "false"`, upgrades apply immediately when detected rather than waiting for shutdown, which prevents leaving the system in a vulnerable state. While services may restart during upgrades, the `AutoFixInterruptedDpkg "true"` setting ensures the package manager recovers from any interrupted configurations automatically.