User guidePatching

Scans and available updates

Every enrolled host scans itself regularly and reports two things: what is installed, and which updates are available to it, for the operating system and for third-party programs. Nothing is installed by a scan.

Scan now

Hosts scan on their own whenever the server asks for a fresh picture. To see the result of a change straight away:

  • one host: open it on Devices and choose Scan now;
  • several hosts: select them on Devices and choose Scan now.

The scan appears on Jobs like any other job, with its live output.

Read the Available updates tab

Open a host and choose Available updates. Security updates are listed first.

  • Security: the vendor marks the update as a security fix.
  • Critical, High and so on: the most serious known vulnerability the update fixes.
  • Advisories and CVEs: the vulnerabilities it closes. One update often fixes many CVEs at once, which is why a host can show far more vulnerabilities than updates.
  • Third-party badges, such as Homebrew or winget: the update is for a program rather than the operating system.
  • Held on host: the host's own administrator pinned the package (for example with apt-mark hold or dnf versionlock). RemediForge never updates it and its checkbox is disabled. To release it, run apt-mark unhold <name> or dnf versionlock delete <name> on the host and scan again.
  • Excluded by policy: a policy's exclusions name the package, so policy runs leave it out. You can still install it by hand.

Reboot required on the host's page means an installed update waits for a restart.

Scans and available updates | RemediForge