Software Sources & Update Strategies
Properly configuring software sources and establishing a sound update strategy are critical to system security and stability. This article explains how to configure software sources and various update strategies in Ubuntu 26.04.
Software Source Basics
Ubuntu 26.04 Source Format
Starting with Ubuntu 24.04, APT source configuration uses the new DEB822 format, with the configuration file located at /etc/apt/sources.list.d/ubuntu.sources:
cat /etc/apt/sources.list.d/ubuntu.sourcesTypical contents:
Types: deb deb-src
URIs: http://archive.ubuntu.com/ubuntu
Suites: resolute resolute-updates resolute-backports
Components: main restricted universe multiverse
Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpgSource Component Descriptions
| Component | Description |
|---|---|
main | Open-source software officially supported by Canonical |
restricted | Proprietary drivers with official support |
universe | Community-maintained open-source software |
multiverse | Software restricted by copyright or legal limitations |
Suite Descriptions
| Suite | Description |
|---|---|
resolute | Base release repository |
resolute-updates | Recommended updates |
resolute-backports | Backported newer software versions |
resolute-security | Security updates |
Switching to a Mirror
# Back up the original configuration
sudo cp /etc/apt/sources.list.d/ubuntu.sources /etc/apt/sources.list.d/ubuntu.sources.bak
# Edit the source configuration
sudo nano /etc/apt/sources.list.d/ubuntu.sourcesReplace the URIs with a mirror:
Types: deb deb-src
URIs: https://mirrors.aliyun.com/ubuntu
Suites: resolute resolute-updates resolute-backports resolute-security
Components: main restricted universe multiverse
Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpgWhen choosing a mirror, prefer one that is geographically and network-close to you. Academic network users may prefer Tsinghua or USTC mirrors, while cloud server users should use their provider’s internal mirrors for the best speeds.
Common mirrors:
| Mirror | URL |
|---|---|
| Alibaba Cloud | https://mirrors.aliyun.com/ubuntu |
| Tsinghua University | https://mirrors.tuna.tsinghua.edu.cn/ubuntu |
| USTC | https://mirrors.ustc.edu.cn/ubuntu |
| Huawei Cloud | https://mirrors.huaweicloud.com/ubuntu |
| Tencent Cloud | https://mirrors.cloud.tencent.com/ubuntu |
After switching, refresh the index:
sudo apt updatePPAs are third-party personally maintained software sources whose packages have not been reviewed by Canonical. Adding untrusted PPAs may introduce security risks or cause dependency conflicts. Only add PPAs from well-known projects, and disable all PPAs before upgrading your system version.
PPA Management
PPAs (Personal Package Archives) allow third-party developers to distribute software packages.
Adding a PPA
# Add a PPA
sudo add-apt-repository ppa:graphics-drivers/ppa
# Update the index after adding
sudo apt update
# Install software from the PPA; choose the version reported by ubuntu-drivers devices
sudo apt install nvidia-driver-XXXRemoving a PPA
# Remove a PPA
sudo add-apt-repository --remove ppa:graphics-drivers/ppa
# Update the index
sudo apt updateManually Adding a Third-Party Source
Using the Docker official source as an example:
# Download the GPG key
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
# Add the repository (DEB822 format)
# Note: Docker's official repository may not yet publish the resolute suite.
# If apt update reports a missing Release file, temporarily fall back to noble.
sudo tee /etc/apt/sources.list.d/docker.sources << 'EOF'
Types: deb
URIs: https://download.docker.com/linux/ubuntu
Suites: resolute
Components: stable
Signed-By: /usr/share/keyrings/docker-archive-keyring.gpg
EOF
# Update and install
sudo apt update
sudo apt install docker-ce docker-ce-cli containerd.ioListing Configured Sources
# View all source files
ls /etc/apt/sources.list.d/
# View all sources used by APT
apt policy
# Check which source a package comes from
apt policy nginxAPT Update Management
Basic Update Commands
# Update the package index
sudo apt update
# Upgrade installed packages
sudo apt upgrade
# Smart upgrade (may install or remove dependencies)
sudo apt full-upgrade
# View upgradable packages without actually upgrading
apt list --upgradable
# Upgrade a specific package
sudo apt install --only-upgrade nginxViewing Update History
# View APT operation history
cat /var/log/apt/history.log
# View compressed history logs
zless /var/log/apt/history.log.1.gz
# View dpkg operation log
cat /var/log/dpkg.logPackage Pinning
To prevent a specific package from being updated:
# Hold a package version
sudo apt-mark hold package-name
# Unhold a package
sudo apt-mark unhold package-name
# View all held packages
apt-mark showholdunattended-upgrades Automatic Updates
Installation and Activation
# Install (usually pre-installed on Ubuntu 26.04)
sudo apt install unattended-upgrades
# Enable automatic updates
sudo dpkg-reconfigure -plow unattended-upgradesConfiguring Automatic Updates
Edit the main configuration file:
sudo nano /etc/apt/apt.conf.d/50unattended-upgradesKey configuration options:
Unattended-Upgrade::Allowed-Origins {
"${distro_id}:${distro_codename}";
"${distro_id}:${distro_codename}-security";
"${distro_id}:${distro_codename}-updates";
// "${distro_id}:${distro_codename}-proposed";
// "${distro_id}:${distro_codename}-backports";
};
// Blacklist packages from auto-updating
Unattended-Upgrade::Package-Blacklist {
"linux-image*";
"linux-headers*";
"nginx";
};
// Automatically remove no-longer-needed dependencies
Unattended-Upgrade::Remove-Unused-Dependencies "true";
// Automatically remove no-longer-needed kernels
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
// Automatically reboot if necessary
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
// Email notifications
Unattended-Upgrade::Mail "admin@example.com";
Unattended-Upgrade::MailReport "on-change";Configure update frequency:
sudo nano /etc/apt/apt.conf.d/20auto-upgradesAPT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";
APT::Periodic::Download-Upgradeable-Packages "1";
APT::Periodic::AutocleanInterval "7";Testing Automatic Updates
# Dry run (does not actually install)
sudo unattended-upgrade --dry-run --debug
# Run automatic updates immediately
sudo unattended-upgrade -v
# View automatic update logs
cat /var/log/unattended-upgrades/unattended-upgrades.logUpdate Strategy Recommendations
Desktop Users
# Recommended: auto-install security updates, manually install feature updates
# /etc/apt/apt.conf.d/20auto-upgrades
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";
APT::Periodic::Download-Upgradeable-Packages "1";
APT::Periodic::AutocleanInterval "7";Periodically check and install updates manually:
sudo apt update && apt list --upgradable
sudo apt upgradeServer Environments
For production servers, it is recommended to:
- Auto-install security updates only; handle other updates manually.
- Set maintenance windows for planned updates.
- Test in a staging environment before applying to production.
- Enable email notifications to stay informed about updates.
# Recommended server configuration
# /etc/apt/apt.conf.d/50unattended-upgrades
Unattended-Upgrade::Allowed-Origins {
"${distro_id}:${distro_codename}-security";
};
Unattended-Upgrade::Automatic-Reboot "false";
Unattended-Upgrade::Mail "admin@example.com";Version Upgrades
Upgrading to a New Ubuntu Version
# Ensure the current system is fully updated
sudo apt update && sudo apt full-upgrade
# Check if a new version is available
do-release-upgrade -c
# Perform the version upgrade
sudo do-release-upgradeCleaning Up After Updates
# Clean the downloaded deb package cache
sudo apt clean
# Remove no-longer-needed dependencies
sudo apt autoremove
# Clean residual configuration files
dpkg -l | grep '^rc' | awk '{print $2}' | xargs sudo dpkg --purge