Seems to be in progress. In the future it will cover 'automatoc security updates'. Anyone have insight into wether this is a good idea and how it's done on something as rolling as an ubuntu server?
The default configuration should work fine for most.
sudo purge-old-kernels
I know on centos, I put this in cron 2x a day:
yum update-minimal --security && curl https://logserver/api/$(hostname)/$(needs-restarting -r)
It grabs all the security based updates, and installs only those. And it reports the reboot required status. I watch that and make a reboot ticket if it hits the true endpoint.
Edit: the server part is just Node-red watching for those endpoint GETs. Once it sees a true, it fires a Jira ticket in the Change Management space for a security based reboot.
Also, I thought the --security flag did not have any effect on CentOS?