Scans and available updates
Every enrolled host scans itself regularly and reports two things: what is installed, and which updates are available to it, for the operating system and for third-party programs. Nothing is installed by a scan.
Scan now
Hosts scan on their own whenever the server asks for a fresh picture. To see the result of a change straight away:
- one host: open it on Devices and choose Scan now;
- several hosts: select them on Devices and choose Scan now.
The scan appears on Jobs like any other job, with its live output.
Read the Available updates tab
Open a host and choose Available updates. Security updates are listed first.
- Security: the vendor marks the update as a security fix.
- Critical, High and so on: the most serious known vulnerability the update fixes.
- Advisories and CVEs: the vulnerabilities it closes. One update often fixes many CVEs at once, which is why a host can show far more vulnerabilities than updates.
- Third-party badges, such as Homebrew or winget: the update is for a program rather than the operating system.
- Held on host: the host's own administrator pinned the package (for
example with
apt-mark holdordnf versionlock). RemediForge never updates it and its checkbox is disabled. To release it, runapt-mark unhold <name>ordnf versionlock delete <name>on the host and scan again. - Excluded by policy: a policy's exclusions name the package, so policy runs leave it out. You can still install it by hand.
Reboot required on the host's page means an installed update waits for a restart.