Fedora DNF¶
Note
DNF 4 is superseded by dnf5 (Fedora’s default since Fedora 41) but stays maintained for the RHEL 8/9 family; mpm wraps dnf5 as a separate manager.
- ID
dnf- Links
- Upstream stars
⭐ 1,383
- Last commit
2026-08-07
- Version requirement
>= 4, < 5
- Platforms
🅱️ BSD · 🐧 Linux · ⨂ Unix
- Operations
installed·outdated·orphans·search·install·upgrade·upgrade_all·remove·sync·cleanup·doctor- purl types
pkg:dnf/·pkg:rpm/- CLI names (lookup order)
dnf·dnf4- Every call
dnf --color=never --quiet <command>- Issues and PRs
- Source
Fedora’s RPM package manager.
The DNF5 and YUM subclasses reuse everything here, differing only in
the binary and forced arguments.
Command equivalences with other managers are listed in Pacman/Rosetta.
What mpm adds to dnf¶
Through mpm, dnf gains --exact and --extended search, to narrow to exact names or match descriptions.
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover dnf alongside dnf5, microdnf, urpmi, yum, zypper and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your dnf commands, in mpm¶
You already know dnf: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
|
|
Remove a package |
|
|
List orphaned dependencies |
|
|
Clear caches |
|
|
Run health checks |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✅ |
|
|
✅ |
|
|
✅ |
|
|
✅ |
Matches names only, with no exact or extended mode. Exact and extended search backfilled by |
|
✅ |
A package already installed as a dependency is marked explicit by |
|
✅ |
|
|
✅ |
|
|
✅ |
Removing a package also drops the dependencies it leaves orphaned, since |
|
✅ |
|
|
✅ |
The |
|
✅ |
Configuration¶
Ignore
dnfon thempmCLI by passing the--no-dnfoption.Ignore it for every run in your configuration:
[mpm] dnf = false
Raise the timeout of all
dnfcalls:[mpm.overrides.dnf] timeout = 900
Run
mpm config-template dnfto print all overridable settings for your configuration file:[mpm.overrides.dnf] cli_names = [ "dnf", "dnf4", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [ "--color=never", "--quiet", ] pre_cmds = [] requirement = ">=4.0.0,<5" stop_on_error = false unmaintained = false version_cli_options = [ "--version", ] version_regexes = [ "dnf5\\s+version\\s+(?P<version>\\S+)", "(?P<version>\\S+)", ]
The arguments and environment variables listed in the box atop this page are forced on every dnf call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Recipes¶
A few jobs you would otherwise script around dnf, one mpm command each:
Snapshot and clone a machine:
mpm --dnf dump dnf.toml, thenmpm restore dnf.tomlon the next one.Export a compliance SBOM:
mpm --dnf sbom(CycloneDX by default,--spdxfor SPDX).Gate CI on health:
mpm --dnf doctorrelays Fedora DNF’s own diagnosis and exits non-zero on trouble.
Privilege escalation¶
System-wide manager: mpm wraps its privileged operations in sudo out of the box. Instead of letting the tool prompt mid-run, mpm primes the credential cache up-front, with a single branded password prompt at most. Turn escalation off for rootless setups with --no-sudo or the per-manager sudo override.
Its privileged operations are cleanup, install, remove, upgrade, upgrade_all.
See privilege escalation for the full policy.
Concurrency¶
mpm never runs dnf at the same time as dnf5, microdnf, urpmi, yum or zypper: they all reach the RPM database, where a second writer either waits for the first one to finish or fails on its lock. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.
Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.
Cooldown¶
State of Fedora DNF’s release-age gating, from the cooldown support table:
Status: ❌ None (effort focused on dnf5)
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: Distro binary archives (
pkg:deb,pkg:rpm,pkg:alpm,pkg:apk)Retraction: Index revert: removal is an archive operation and the mirror is rebuilt without the package. Debian, for one, requires filing an
RM:bug againstftp.debian.org(developers-reference)Publish date: ❌ the version string is the distro maintainer’s build, carrying no upstream publication date
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Reference traces¶
A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Fedora DNF well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ dnf --color=never --quiet repoquery --userinstalled --qf {format}
NetworkManager-bluetooth___MPM___1.56.1___MPM___Bluetooth device plugin for NetworkManager___MPM___aarch64
NetworkManager-team___MPM___1.56.1___MPM___Team device plugin for NetworkManager___MPM___aarch64
NetworkManager-wifi___MPM___1.56.1___MPM___Wifi plugin for NetworkManager___MPM___aarch64
$ dnf --color=never --quiet repoquery --installed --qf {format}
librepo___MPM___1.21.0-1.fc44___MPM___Repodata downloading library___MPM___aarch64
openldap___MPM___2.6.13-1.fc44___MPM___LDAP support libraries___MPM___aarch64
wireless-regdb___MPM___2026.05.30-1.fc44___MPM___Regulatory database for 802.11 wireless networking___MPM___noarch
$ dnf --color=never --quiet repoquery --upgrades --qf {format}
librepo___MPM___1.21.0-2.fc44___MPM___Repodata downloading library___MPM___aarch64
openldap___MPM___2.6.14-1.fc44___MPM___LDAP support libraries___MPM___aarch64
wireless-regdb___MPM___2026.09.03-1.fc44___MPM___Regulatory database for 802.11 wireless networking___MPM___noarch
$ dnf --color=never --quiet repoquery --unneeded
bc-0:1.08.2-4.fc44.aarch64
dos2unix-0:7.5.6-1.fc44.aarch64
tree-0:2.2.1-4.fc44.aarch64
Version check¶
The version is extracted from the output of dnf --version with the first of these regular expressions to match:
r"dnf5\s+version\s+(?P<version>\S+)"
r"(?P<version>\S+)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Mark a package already installed as a dependency as explicitly installed when
mpm installormpm restorenames it, sompm cleanup --orphanskeeps it.Fix version detection against
dnf5, whose banner was read as the versiondnf5, dropping every RPM front-end from the pool on Fedora 41 and later.Fix
searchondnf5, which returned no results at all, andoutdated, which reported the upgrade candidate’s own version as the installed one.Decline a
dnf5binary reached through thednfname, leaving it to thednf5manager instead of reporting the same RPM database twice.Correct the commands shown on each manager’s page, which named fewer options than
mpmactually runs.
7.4.0(2026-07-25)Plain
cleanupno longer removes orphaned packages: their native sweeps moved behindcleanup --orphans. This also stopsemerge’s cleanup from triggering its pre-depclean world upgrade unless--orphansis given.removeno longer cascades to orphaned dependencies by default: a plain removal keeps them. Use the newremove --orphansto restore the previous behavior.cleanup --cachenow escalates throughsudo:dnf clean allclears the root-owned package cache.
7.1.0(2026-07-07)upgradeandupgrade --allnow pass--assumeyes, as the other dnf operations already did, so upgrades no longer hang on an interactive confirmation prompt.
6.2.0(2026-03-25)Add
--quietoption to all invocations to reduce log verbosity.
5.19.0(2024-11-14)Implement
removeoperation.Use query template instead of regex parsing to retrieve package data.
4.12.0(2022-04-04)