User guidePatching

Scans and available updates

Every enrolled host scans itself regularly and reports two things: what is installed, and which updates its package manager offers. Nothing is installed by a scan.

Host What is checked
Ubuntu, Debian apt
RHEL, Rocky, Alma, Oracle Linux, CentOS dnf or yum
Windows Windows Update, and third-party programs through winget
macOS Apple Software Update and Homebrew

Scan now

Hosts scan on their own whenever the server asks for a fresh picture. To see the result of a change straight away:

  • one host: open it on Devices and choose Scan now;
  • several hosts: select them on Devices and choose Scan now.

The scan appears on Jobs like any other job, with its live output.

Read the Available updates tab

Open a host and choose Available updates. Security updates are listed first.

  • Security: the vendor marks the update as a security fix.
  • Critical, High and so on: the most serious known vulnerability the update fixes.
  • Advisories and CVEs: the vulnerabilities it closes. One update often fixes many CVEs at once, which is why a host can show far more vulnerabilities than updates.
  • Homebrew, winget and similar badges: the update comes from that package source rather than the operating system.
  • Held on host: the host's own administrator pinned the package (for example with apt-mark hold or dnf versionlock). PatchPilot never updates it and its checkbox is disabled. To release it, run apt-mark unhold <name> or dnf versionlock delete <name> on the host and scan again.
  • Excluded by policy: a policy's exclusions name the package, so policy runs leave it out. You can still install it by hand.

Reboot required on the host's page means an installed update waits for a restart.