Fedora DNF

Note

DNF 4 is superseded by dnf5 (Fedora’s default since Fedora 41) but stays maintained for the RHEL 8/9 family; mpm wraps dnf5 as a separate manager.

ID

dnf

Links

Documentation · Repository · Wikipedia

Upstream stars

⭐ 1,383

Last commit

2026-08-07

Version requirement

>= 4, < 5

Platforms

🅱️ BSD · 🐧 Linux · ⨂ Unix

Operations

installed · outdated · orphans · search · install · upgrade · upgrade_all · remove · sync · cleanup · doctor

purl types

pkg:dnf/ · pkg:rpm/

CLI names (lookup order)

dnf · dnf4

Every call

dnf --color=never --quiet <command>

Issues and PRs

📦 manager: rpm-based

Source

dnf.py

Fedora’s RPM package manager.

The DNF5 and YUM subclasses reuse everything here, differing only in the binary and forced arguments.

Command equivalences with other managers are listed in Pacman/Rosetta.

What mpm adds to dnf

Through mpm, dnf gains --exact and --extended search, to narrow to exact names or match descriptions.

Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover dnf alongside dnf5, microdnf, urpmi, yum, zypper and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your dnf commands, in mpm

You already know dnf: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With dnf

With mpm

List what’s installed

dnf repoquery --userinstalled --qf <format>

mpm --dnf installed

List outdated packages

dnf repoquery --installed --qf <format>

mpm --dnf outdated

Search for a package

dnf4 search usd

mpm --dnf search usd

Install a package

sudo dnf --assumeyes install pip

mpm install pkg:dnf/pip

Upgrade one package

sudo dnf --assumeyes upgrade pip

mpm --dnf upgrade pip

Upgrade everything

sudo dnf --assumeyes upgrade

mpm --dnf upgrade --all

Remove a package

sudo dnf --assumeyes remove pip

mpm remove pkg:dnf/pip

List orphaned dependencies

dnf repoquery --unneeded

mpm --dnf orphans

Clear caches

sudo dnf clean all

mpm --dnf cleanup --cache

Run health checks

dnf check

mpm --dnf doctor

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

outdated

✅

orphans

✅

search

✅

Matches names only, with no exact or extended mode. Exact and extended search backfilled by mpm.

install

✅

A package already installed as a dependency is marked explicit by mpm.

upgrade

✅

upgrade_all

✅

remove

✅

Removing a package also drops the dependencies it leaves orphaned, since remove runs autoremove. The --orphans flag also drops the package’s orphaned dependencies.

sync

✅

cleanup

✅

The --orphans flag runs the system-wide orphan sweep.

doctor

✅

Configuration

  • Ignore dnf on the mpm CLI by passing the --no-dnf option.

  • Ignore it for every run in your configuration:

    [mpm]
    dnf = false
    
  • Raise the timeout of all dnf calls:

    [mpm.overrides.dnf]
    timeout = 900
    
  • Run mpm config-template dnf to print all overridable settings for your configuration file:

    [mpm.overrides.dnf]
    cli_names = [
        "dnf",
        "dnf4",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = []
    pre_args = [
        "--color=never",
        "--quiet",
    ]
    pre_cmds = []
    requirement = ">=4.0.0,<5"
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "dnf5\\s+version\\s+(?P<version>\\S+)",
        "(?P<version>\\S+)",
    ]
    

The arguments and environment variables listed in the box atop this page are forced on every dnf call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.

Recipes

A few jobs you would otherwise script around dnf, one mpm command each:

  • Snapshot and clone a machine: mpm --dnf dump dnf.toml, then mpm restore dnf.toml on the next one.

  • Export a compliance SBOM: mpm --dnf sbom (CycloneDX by default, --spdx for SPDX).

  • Gate CI on health: mpm --dnf doctor relays Fedora DNF’s own diagnosis and exits non-zero on trouble.

Privilege escalation

System-wide manager: mpm wraps its privileged operations in sudo out of the box. Instead of letting the tool prompt mid-run, mpm primes the credential cache up-front, with a single branded password prompt at most. Turn escalation off for rootless setups with --no-sudo or the per-manager sudo override.

Its privileged operations are cleanup, install, remove, upgrade, upgrade_all.

See privilege escalation for the full policy.

Concurrency

mpm never runs dnf at the same time as dnf5, microdnf, urpmi, yum or zypper: they all reach the RPM database, where a second writer either waits for the first one to finish or fails on its lock. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.

Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.

Cooldown

State of Fedora DNF’s release-age gating, from the cooldown support table:

Status: ❌ None (effort focused on dnf5)

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: Distro binary archives (pkg:deb, pkg:rpm, pkg:alpm, pkg:apk)

  • Retraction: Index revert: removal is an archive operation and the mirror is rebuilt without the package. Debian, for one, requires filing an RM: bug against ftp.debian.org (developers-reference)

  • Publish date: ❌ the version string is the distro maintainer’s build, carrying no upstream publication date

With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.

Reference traces

A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Fedora DNF well and a transcript below looks wrong, or a newer release changed its output format, report it.

$ dnf --color=never --quiet repoquery --userinstalled --qf {format}
NetworkManager-bluetooth___MPM___1.56.1___MPM___Bluetooth device plugin for NetworkManager___MPM___aarch64
NetworkManager-team___MPM___1.56.1___MPM___Team device plugin for NetworkManager___MPM___aarch64
NetworkManager-wifi___MPM___1.56.1___MPM___Wifi plugin for NetworkManager___MPM___aarch64
$ dnf --color=never --quiet repoquery --installed --qf {format}
librepo___MPM___1.21.0-1.fc44___MPM___Repodata downloading library___MPM___aarch64
openldap___MPM___2.6.13-1.fc44___MPM___LDAP support libraries___MPM___aarch64
wireless-regdb___MPM___2026.05.30-1.fc44___MPM___Regulatory database for 802.11 wireless networking___MPM___noarch
$ dnf --color=never --quiet repoquery --upgrades --qf {format}
librepo___MPM___1.21.0-2.fc44___MPM___Repodata downloading library___MPM___aarch64
openldap___MPM___2.6.14-1.fc44___MPM___LDAP support libraries___MPM___aarch64
wireless-regdb___MPM___2026.09.03-1.fc44___MPM___Regulatory database for 802.11 wireless networking___MPM___noarch
$ dnf --color=never --quiet repoquery --unneeded
bc-0:1.08.2-4.fc44.aarch64
dos2unix-0:7.5.6-1.fc44.aarch64
tree-0:2.2.1-4.fc44.aarch64

Version check

The version is extracted from the output of dnf --version with the first of these regular expressions to match:

r"dnf5\s+version\s+(?P<version>\S+)"
r"(?P<version>\S+)"

Upstream project

Metrics

rpm-software-management/dnf

Activity

commit activity commits since open issues open pull requests

Popularity

forks watchers contributors

Metadata

latest release release date license main language

Changelog

  • 8.0.0 (2026-09-20)

    • Mark a package already installed as a dependency as explicitly installed when mpm install or mpm restore names it, so mpm cleanup --orphans keeps it.

    • Fix version detection against dnf5, whose banner was read as the version dnf5, dropping every RPM front-end from the pool on Fedora 41 and later.

    • Fix search on dnf5, which returned no results at all, and outdated, which reported the upgrade candidate’s own version as the installed one.

    • Decline a dnf5 binary reached through the dnf name, leaving it to the dnf5 manager instead of reporting the same RPM database twice.

    • Correct the commands shown on each manager’s page, which named fewer options than mpm actually runs.

  • 7.4.0 (2026-07-25)

    • Plain cleanup no longer removes orphaned packages: their native sweeps moved behind cleanup --orphans. This also stops emerge’s cleanup from triggering its pre-depclean world upgrade unless --orphans is given.

    • remove no longer cascades to orphaned dependencies by default: a plain removal keeps them. Use the new remove --orphans to restore the previous behavior.

    • cleanup --cache now escalates through sudo: dnf clean all clears the root-owned package cache.

  • 7.1.0 (2026-07-07)

    • upgrade and upgrade --all now pass --assumeyes, as the other dnf operations already did, so upgrades no longer hang on an interactive confirmation prompt.

  • 6.2.0 (2026-03-25)

    • Add --quiet option to all invocations to reduce log verbosity.

  • 5.19.0 (2024-11-14)

    • Implement remove operation.

    • Use query template instead of regex parsing to retrieve package data.

  • 4.12.0 (2022-04-04)

    • Add support for dnf. Closes #516, refs #415.