Automatic Security Updates

Bug #1551373 reported by Cassidy James Blaede
280
This bug affects 6 people
Affects Status Importance Assigned to Milestone
AppCenter
Confirmed
Wishlist
Unassigned

Bug Description

We should ensure that automatic security updates are enabled out of the box in elementary OS. Security vulnerabilities are found, fixed, and released upstream frequently enough that we really should just deliver these automatically.

One concern that has been raised is bandwidth caps; I agree that not *all* updates should necessarily be automatic (especially on metered connections), but the counterargument for pushing automatic security updates is that if the user's system is online at all, it's not safe unless they have the latest security updates.

unattended-upgrade might be one route (see: https://help.ubuntu.com/community/AutomaticSecurityUpdates) but I believe Cody said he was investigating an apt config instead.

Changed in elementaryos:
status: New → Confirmed
milestone: none → loki-beta1
assignee: nobody → Cody Garver (codygarver)
information type: Public → Public Security
Revision history for this message
Cody Garver (codygarver) wrote :

After some research and consideration I decided it would be dangerous for us to do background updates, since the system could shutdown unknowingly or lose power during an upgrade. So there would need to be some kind of GUI inhibiting an unsafe shutdown. And our GUI for installing updates is appcenter, so it's the logical place for this to happen. What exactly this should look like, I'm not sure.

affects: elementaryos → appcenter
Changed in appcenter:
assignee: Cody Garver (codygarver) → nobody
importance: Undecided → Wishlist
milestone: loki-beta1 → none
milestone: none → loki-beta1
Revision history for this message
ceg (ceg) wrote :

Is the setting under "Applications" -> "Software updater" -> "Settings..." -> "When there are security updates" -> "Download and install automatically" not working?

The updater should lock (i.e delay) any requested standby or shutdown operation while applying updates (not yet when downloading).

Revision history for this message
ceg (ceg) wrote :

The package "unattended-upgrades" seems to support delaying shutdowns:
http://askubuntu.com/questions/251303/how-to-automatically-install-updates-before-shutdown

Changed in appcenter:
milestone: loki-beta1 → none
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.