Skip to Content
DocsReferenceCommand Referenceapt

apt Common Commands

Repository Updates

CommandDescription
sudo apt updateUpdate package index
sudo apt upgradeUpgrade all installed packages
sudo apt full-upgradeUpgrade packages and automatically handle dependency changes
sudo apt dist-upgradeSame as full-upgrade

Install and Remove

CommandDescription
sudo apt install package-nameInstall a package
sudo apt install package-name=versionInstall a specific version
sudo apt install ./package.debInstall a local .deb file
sudo apt reinstall package-nameReinstall a package
sudo apt remove package-nameRemove a package (keep configuration)
sudo apt purge package-nameRemove a package and delete configuration files
sudo apt autoremoveRemove dependencies that are no longer needed

Search and Query

CommandDescription
apt search keywordSearch for packages
apt show package-nameShow package details
apt list --installedList installed packages
apt list --upgradableList upgradable packages
apt depends package-nameShow dependencies
apt rdepends package-nameShow reverse dependencies
dpkg -L package-nameList all files installed by a package
dpkg -S /path/to/fileFind which package owns a file

Cache Cleanup

CommandDescription
sudo apt cleanClear all downloaded cache
sudo apt autocleanClear only outdated cache
sudo apt autoremove --purgeRemove dependencies and purge configuration

Version Pinning

CommandDescription
sudo apt-mark hold package-nameHold a package version (prevent upgrades)
sudo apt-mark unhold package-nameUnhold a package
apt-mark showholdShow held packages

Repair

CommandDescription
sudo apt --fix-broken installFix dependencies
sudo dpkg --configure -aReconfigure interrupted packages

Repository Management

CommandDescription
sudo add-apt-repository ppa:xxx/yyyAdd a PPA
sudo add-apt-repository --remove ppa:xxx/yyyRemove a PPA
cat /etc/apt/sources.list.d/ubuntu.sourcesView configured sources
grep -rh "^deb " /etc/apt/sources.list.d/List all sources

Signing Third-Party Repositories (apt-key removed)

APT 3.1 has fully removed apt-key, and the global keyring is no longer trusted. When adding a third-party repository, store the key separately in /etc/apt/keyrings/ and point to it explicitly with Signed-By in the source entry.

# 1. Download the key and convert it to a binary keyring (de-armored) sudo install -d -m 0755 /etc/apt/keyrings curl -fsSL https://example.com/repo.gpg \ | sudo gpg --dearmor -o /etc/apt/keyrings/example.gpg sudo chmod 0644 /etc/apt/keyrings/example.gpg

Prefer the deb822 format (.sources files), binding the key with Signed-By:

# /etc/apt/sources.list.d/example.sources Types: deb URIs: https://example.com/apt Suites: noble Components: main Signed-By: /etc/apt/keyrings/example.gpg

For the legacy one-line format (.list files), use the signed-by= option:

# /etc/apt/sources.list.d/example.list deb [arch=amd64 signed-by=/etc/apt/keyrings/example.gpg] https://example.com/apt noble main
Tip

Giving each repository its own keyring that signs only its own repository prevents one third-party key from being used to forge official packages — far safer than the old global apt-key.

Simulation and Download

CommandDescription
apt install -s package-nameSimulate installation (dry run)
apt download package-nameDownload without installing

Useful Tips

CommandDescription
apt changelog package-nameView package changelog
apt policy package-nameShow which repository provides the package
grep ^Package /var/lib/apt/lists/repo-name*_Packages | sort -uList all packages from a specific repository
Last updated on