Debian apt¶
- ID
apt- Links
- Upstream stars
⭐ 67
- Last commit
2026-09-24
- Version requirement
>= 1
- Platforms
🅱️ BSD · 🐧 Linux · ⨂ Unix
- Operations
installed·outdated·orphans·search·install·upgrade·upgrade_all·remove·sync·cleanup·doctor- purl types
pkg:apt/·pkg:deb/- CLI name
apt- Every call
apt --quiet <command>- Issues and PRs
- Source
Base class for Debian’s apt front-end and its variants.
Command equivalences with other managers are listed in Pacman/Rosetta.
mpm drives the high-level apt binary, not apt-get or apt-cache,
over system-wide packages. Mutations escalate through sudo and force
--yes to stay non-interactive. APT_Mint retargets Linux
Mint’s same-named but differently-behaved apt.
What mpm adds to apt¶
mpm reaches across every manager at once, not apt alone: mpm installed and mpm outdated cover apt alongside apt-mint, aptitude, nala and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your apt commands, in mpm¶
You already know apt: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
|
|
Remove a package |
|
|
List orphaned dependencies |
|
|
Clear caches |
|
|
Run health checks |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✅ |
|
|
✅ |
|
|
✅ |
|
|
✅ |
|
|
✅ |
A package already installed as a dependency is marked explicit by |
|
✅ |
|
|
✅ |
|
|
✅ |
The |
|
✅ |
|
|
✅ |
The |
|
✅ |
Configuration¶
Ignore
apton thempmCLI by passing the--no-aptoption.Ignore it for every run in your configuration:
[mpm] apt = false
Raise the timeout of all
aptcalls:[mpm.overrides.apt] timeout = 900
Run
mpm config-template aptto print all overridable settings for your configuration file:[mpm.overrides.apt] cli_names = [ "apt", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [ "--quiet", ] pre_cmds = [] requirement = ">=1.0.0" stop_on_error = false unmaintained = false version_cli_options = [ "--version", ] version_regexes = [ "apt\\s+(?P<version>\\S+)", ]
The arguments and environment variables listed in the box atop this page are forced on every apt call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Recipes¶
A few jobs you would otherwise script around apt, one mpm command each:
Snapshot and clone a machine:
mpm --apt dump apt.toml, thenmpm restore apt.tomlon the next one.Export a compliance SBOM:
mpm --apt sbom(CycloneDX by default,--spdxfor SPDX).Gate CI on health:
mpm --apt doctorrelays Debian apt’s own diagnosis and exits non-zero on trouble.
Privilege escalation¶
System-wide manager: mpm wraps its privileged operations in sudo out of the box. Instead of letting the tool prompt mid-run, mpm primes the credential cache up-front, with a single branded password prompt at most. Turn escalation off for rootless setups with --no-sudo or the per-manager sudo override.
Its privileged operations are cleanup, install, remove, sync, upgrade, upgrade_all.
See privilege escalation for the full policy.
Concurrency¶
mpm never runs apt at the same time as apt-mint, aptitude, deb-get, nala or pacstall: they all install through dpkg and serialize on its /var/lib/dpkg/lock. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.
Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.
Cooldown¶
State of Debian apt’s release-age gating, from the cooldown support table:
Status: ➖ N/A (Debian’s
unstable→testing→stablemigration is functionally similar)Reference: Nesbitt, Package managers need to cool down
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: Distro binary archives (
pkg:deb,pkg:rpm,pkg:alpm,pkg:apk)Retraction: Index revert: removal is an archive operation and the mirror is rebuilt without the package. Debian, for one, requires filing an
RM:bug againstftp.debian.org(developers-reference)Publish date: ❌ the version string is the distro maintainer’s build, carrying no upstream publication date
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Reference traces¶
A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Debian apt well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ apt --quiet list --installed
Listing...
adduser/xenial,now 3.113+nmu3ubuntu4 all [installed]
bc/xenial,now 1.06.95-9build1 amd64 [installed]
bsdmainutils/xenial,now 9.0.6ubuntu3 amd64 [installed,automatic]
ca-certificates/xenial,now 20160104ubuntu1 all [installed]
cron/xenial,now 3.0pl1-128ubuntu2 amd64 [installed]
debconf/xenial,now 1.5.58ubuntu1 all [installed]
debianutils/xenial,now 4.7 amd64 [installed]
diffutils/xenial,now 1:3.3-3 amd64 [installed]
e2fsprogs/xenial,now 1.42.13-1ubuntu1 amd64 [installed]
ethstatus/xenial,now 0.4.3ubuntu2 amd64 [installed]
file/xenial,now 1:5.25-2ubuntu1 amd64 [installed]
findutils/xenial,now 4.6.0+git+20160126-2 amd64 [installed]
libidn2-0/jammy,now 2.3.2-2build1 amd64 [installed,automatic]
libidn2-0/jammy,now 2.3.2-2build1 i386 [installed,automatic]
$ apt --quiet list --upgradable
Listing...
apt/xenial-updates 1.2.19 amd64 [upgradable from: 1.2.15ubuntu0.2]
nano/xenial-updates 2.5.3-2ubuntu2 amd64 [upgradable from: 2.5.3-2]
$ apt --quiet autoremove --simulate
NOTE: This is only a simulation!
apt needs root privileges for real execution.
Keep also in mind that locking is deactivated,
so don't depend on the relevance to the real current situation!
Reading package lists...
Building dependency tree...
Reading state information...
The following packages will be REMOVED:
libx11-dev libxcb1-dev
0 upgraded, 0 newly installed, 2 to remove and 0 not upgraded.
Remv libx11-dev [2:1.8.7-1]
Remv libxcb1-dev [1.15-1]
Version check¶
The version is probed by running:
$ apt --version
apt 2.0.6 (amd64)
and extracted with:
r"apt\s+(?P<version>\S+)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Mark a package already installed as a dependency as explicitly installed when
mpm installormpm restorenames it, sompm cleanup --orphanskeeps it.
7.4.0(2026-07-25)Plain
cleanupno longer removes orphaned packages: their native sweeps moved behindcleanup --orphans. This also stopsemerge’s cleanup from triggering its pre-depclean world upgrade unless--orphansis given.
6.4.0(2026-04-27)Add
removeoperation. Closes #1775.
5.18.0(2024-08-02)Add architecture in package metadata.
5.13.1(2023-05-06)Fix omission of the final result in an
apt(non-mint) search.
5.13.0(2023-04-04)5.0.1(2022-04-28)Fix commands incompatible with
--yesoption. Closes #625.
4.13.1(2022-04-17)4.4.0(2021-09-27)Add dedicated
apt-mintmanager to handle the special case ofapton Linux Mint.
3.0.0(2020-03-25)2.6.0(2017-09-10)Add support for
apton Linux systems.