Scans and available updates
Every enrolled host scans itself regularly and reports two things: what is installed, and which updates its package manager offers. Nothing is installed by a scan.
| Host | What is checked |
|---|---|
| Ubuntu, Debian | apt |
| RHEL, Rocky, Alma, Oracle Linux, CentOS | dnf or yum |
| Windows | Windows Update, and third-party programs through winget |
| macOS | Apple Software Update and Homebrew |
Scan now
Hosts scan on their own whenever the server asks for a fresh picture. To see the result of a change straight away:
- one host: open it on Devices and choose Scan now;
- several hosts: select them on Devices and choose Scan now.
The scan appears on Jobs like any other job, with its live output.
Read the Available updates tab
Open a host and choose Available updates. Security updates are listed first.
- Security: the vendor marks the update as a security fix.
- Critical, High and so on: the most serious known vulnerability the update fixes.
- Advisories and CVEs: the vulnerabilities it closes. One update often fixes many CVEs at once, which is why a host can show far more vulnerabilities than updates.
- Homebrew, winget and similar badges: the update comes from that package source rather than the operating system.
- Held on host: the host's own administrator pinned the package (for
example with
apt-mark holdordnf versionlock). PatchPilot never updates it and its checkbox is disabled. To release it, runapt-mark unhold <name>ordnf versionlock delete <name>on the host and scan again. - Excluded by policy: a policy's exclusions name the package, so policy runs leave it out. You can still install it by hand.
Reboot required on the host's page means an installed update waits for a restart.