Recommended Free Tools
To check for available Debian updates, refresh APT’s package indexes, list packages with newer versions, then review and install the proposed upgrades:
sudo apt update
apt list --upgradable
sudo apt upgrade
The list shows available package upgrades from your configured repositories; it does not identify every item as a security fix. For security-specific status, check Debian’s advisories and confirm your system has the correct security archive configured.
Before checking: confirm your release and APT sources
APT can find only updates offered by the package sources configured on your computer. If the security archive for your Debian release is missing or incorrectly configured, an update check may not show the relevant security packages.
Check which Debian release the machine runs and inspect its APT sources before changing them, particularly if the system is older, was upgraded between releases, or uses third-party repositories. Debian’s security suite naming has changed over time; for Bullseye and later, the suite uses the codename-security form. Do not copy a suite name or codename from an older example without checking your system’s release and current Debian guidance. See the Debian Handbook’s APT guidance.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
Refresh the package list
sudo apt update
This command downloads current package indexes from configured sources. Look for failed repositories, signature errors, or unreachable servers in the output. If a source could not be refreshed, APT cannot show the newest packages from that source. Debian recommends updating package lists before package-management operations; see the Debian AptCLI guidance.
List packages with available upgrades
apt list --upgradable
The output lists installed packages for which configured repositories offer a newer version. It can include security fixes, bug fixes, and other updates. The command does not classify each entry as a security update. Debian documents this command in the Debian FAQ on package management.
Rank #2
To determine whether an available version addresses a security issue, check Debian Security Information and the relevant advisory. Debian publishes security information separately from the general list of package upgrades.
Install routine updates with apt upgrade
sudo apt upgrade
Read APT’s proposed transaction before confirming it. The routine upgrade command upgrades installed packages without removing packages or installing new ones to satisfy dependency changes. As a result, packages that need broader dependency changes may be held back. Debian explains the distinction in its package-management FAQ and APT Handbook chapter.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Choose between apt upgrade and apt full-upgrade
| Command | Purpose | What to review |
|---|---|---|
apt upgrade |
Routine upgrade of installed packages. | Review the transaction summary. It avoids removals and new package installs; some upgrades may remain held back. |
apt full-upgrade |
Broader dependency resolution when packages cannot be upgraded by the routine command. | It can install new dependencies and remove packages. Inspect every proposed addition and removal before accepting. |
If packages are held back, investigate why before choosing a broader upgrade. Use sudo apt full-upgrade only if its proposed changes are appropriate for the machine and its services; Debian describes this as the more significant upgrade option in its FAQ and Handbook.
Verify the result
Check the command output for errors and packages that could not be upgraded. APT and dpkg record package activity in logs including /var/log/apt/history.log, /var/log/apt/term.log, and /var/log/dpkg.log, as described in the Debian Handbook. On production or otherwise availability-sensitive systems, follow your backup, maintenance-window, change-control, and service-restart procedures.
Rank #4
Optional: automate updates with unattended-upgrades
Debian provides unattended-upgrades as an option for automatically installing updates from configured APT sources. Its scope can be customized, and the presence of the package alone does not establish that automatic updates are enabled or configured as intended. Check the package’s configuration and logs as part of managing the system. The Debian Security Information page describes the option; the Debian trixie man page documents its source behavior and logging. Debian’s Handbook guidance on keeping a system up to date also discusses automation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

