apt Common Commands
Repository Updates
| Command | Description |
|---|---|
sudo apt update | Update package index |
sudo apt upgrade | Upgrade all installed packages |
sudo apt full-upgrade | Upgrade packages and automatically handle dependency changes |
sudo apt dist-upgrade | Same as full-upgrade |
Install and Remove
| Command | Description |
|---|---|
sudo apt install package-name | Install a package |
sudo apt install package-name=version | Install a specific version |
sudo apt install ./package.deb | Install a local .deb file |
sudo apt reinstall package-name | Reinstall a package |
sudo apt remove package-name | Remove a package (keep configuration) |
sudo apt purge package-name | Remove a package and delete configuration files |
sudo apt autoremove | Remove dependencies that are no longer needed |
Search and Query
| Command | Description |
|---|---|
apt search keyword | Search for packages |
apt show package-name | Show package details |
apt list --installed | List installed packages |
apt list --upgradable | List upgradable packages |
apt depends package-name | Show dependencies |
apt rdepends package-name | Show reverse dependencies |
dpkg -L package-name | List all files installed by a package |
dpkg -S /path/to/file | Find which package owns a file |
Cache Cleanup
| Command | Description |
|---|---|
sudo apt clean | Clear all downloaded cache |
sudo apt autoclean | Clear only outdated cache |
sudo apt autoremove --purge | Remove dependencies and purge configuration |
Version Pinning
| Command | Description |
|---|---|
sudo apt-mark hold package-name | Hold a package version (prevent upgrades) |
sudo apt-mark unhold package-name | Unhold a package |
apt-mark showhold | Show held packages |
Repair
| Command | Description |
|---|---|
sudo apt --fix-broken install | Fix dependencies |
sudo dpkg --configure -a | Reconfigure interrupted packages |
Repository Management
| Command | Description |
|---|---|
sudo add-apt-repository ppa:xxx/yyy | Add a PPA |
sudo add-apt-repository --remove ppa:xxx/yyy | Remove a PPA |
cat /etc/apt/sources.list.d/ubuntu.sources | View configured sources |
grep -rh "^deb " /etc/apt/sources.list.d/ | List all sources |
Signing Third-Party Repositories (apt-key removed)
APT 3.1 has fully removed apt-key, and the global keyring is no longer trusted. When adding a third-party repository, store the key separately in /etc/apt/keyrings/ and point to it explicitly with Signed-By in the source entry.
# 1. Download the key and convert it to a binary keyring (de-armored)
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://example.com/repo.gpg \
| sudo gpg --dearmor -o /etc/apt/keyrings/example.gpg
sudo chmod 0644 /etc/apt/keyrings/example.gpgPrefer the deb822 format (.sources files), binding the key with Signed-By:
# /etc/apt/sources.list.d/example.sources
Types: deb
URIs: https://example.com/apt
Suites: noble
Components: main
Signed-By: /etc/apt/keyrings/example.gpgFor the legacy one-line format (.list files), use the signed-by= option:
# /etc/apt/sources.list.d/example.list
deb [arch=amd64 signed-by=/etc/apt/keyrings/example.gpg] https://example.com/apt noble mainTip
Giving each repository its own keyring that signs only its own repository prevents one third-party key from being used to forge official packages — far safer than the old global apt-key.
Simulation and Download
| Command | Description |
|---|---|
apt install -s package-name | Simulate installation (dry run) |
apt download package-name | Download without installing |
Useful Tips
| Command | Description |
|---|---|
apt changelog package-name | View package changelog |
apt policy package-name | Show which repository provides the package |
grep ^Package /var/lib/apt/lists/repo-name*_Packages | sort -u | List all packages from a specific repository |
Last updated on