Fedora DNF5¶
- ID
dnf5- Home page
- Upstream stars
⭐ 469
- Last commit
2026-09-07
- Version requirement
>= 5
- Platforms
🅱️ BSD · 🐧 Linux · ⨂ Unix
- Operations
installed·outdated·orphans·search·install·upgrade·upgrade_all·remove·sync·cleanup·doctor- purl types
pkg:dnf5·pkg:rpm- CLI name
dnf5- Every call
dnf5 --quiet <command>- Issues and PRs
- Source
The dnf5 rewrite of DNF, Fedora’s reference package manager since
Fedora 41.
Inherits every operation and parser from DNF. Its forced arguments drop
--color=never (dnf5 rejects that option), keeping only --quiet.
What mpm adds to dnf5¶
Through mpm, dnf5 gains --exact and --extended search, to narrow to exact names or match descriptions.
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover dnf5 alongside dnf, yum, zypper and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your dnf5 commands, in mpm¶
You already know dnf5: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
|
|
Remove a package |
|
|
List orphaned dependencies |
|
|
Clear caches |
|
|
Run health checks |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
exact and extended search backfilled by |
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
Selecting and configuring dnf5¶
Deselect dnf5 for a single run with --no-dnf5, or persist the choice in your configuration:
[mpm]
dnf5 = false
The arguments and environment variables listed in the box atop this page are forced on every dnf5 call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Keep it enabled but tune how mpm drives it with a per-manager override:
[mpm.overrides.dnf5]
timeout = 900
mpm config-template dnf5 prints every overridable attribute as a ready-to-paste block.
Recipes¶
A few jobs you would otherwise script around dnf5, one mpm command each:
Snapshot and clone a machine:
mpm --dnf5 dump dnf5.toml, thenmpm restore dnf5.tomlon the next one.Export a compliance SBOM:
mpm --dnf5 sbom(CycloneDX by default,--spdxfor SPDX).Gate CI on health:
mpm --dnf5 doctorrelays Fedora DNF5’s own diagnosis and exits non-zero on trouble.
Privilege escalation¶
System-wide manager: mpm wraps its privileged operations in sudo out of the box. Instead of letting the tool prompt mid-run, mpm primes the credential cache up-front, with a single branded password prompt at most. Turn escalation off for rootless setups with --no-sudo or the per-manager sudo override.
See privilege escalation for the full policy.
Concurrency¶
mpm never runs dnf5 at the same time as dnf, urpmi, yum or zypper: they all reach the RPM database, and a second writer waits on its lock for as long as the first one holds it, rather than failing. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.
Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.
Cooldown¶
State of Fedora DNF5’s release-age gating, from the cooldown support table:
Status: 🚧 Proposed
Mechanism:
minimum_package_age(open issue)Reference: rpm-software-management/dnf5#2743
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: Distro binary archives (
pkg:deb,pkg:rpm,pkg:alpm,pkg:apk)Retraction: Index revert: removal is an archive operation and the mirror is rebuilt without the package. Debian, for one, requires filing an
RM:bug againstftp.debian.org(developers-reference)Publish date: ❌ the version string is the distro maintainer’s build, carrying no upstream publication date
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Version probe¶
The version is probed by running:
$ dnf5 --version
dnf5 version 5.4.3.0
dnf5 plugin API version 2.0
libdnf5 version 5.4.3.0
libdnf5 plugin API version 2.2
and extracted with:
r"dnf5\s+version\s+(?P<version>\S+)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0.dev0(unreleased)Fix version detection against
dnf5, whose banner was read as the versiondnf5, dropping every RPM front-end from the pool on Fedora 41 and later.Fix
searchondnf5, which returned no results at all, and keep whole package descriptions instead of their first word.Fix
outdated, which reported the upgrade candidate’s own version as the installed one, and now names the epoch and release both sides differ by.
7.4.0(2026-07-25)Plain
cleanupno longer removes orphaned packages: their native sweeps moved behindcleanup --orphans. This also stopsemerge’s cleanup from triggering its pre-depclean world upgrade unless--orphansis given.removeno longer cascades to orphaned dependencies by default: a plain removal keeps them. Use the newremove --orphansto restore the previous behavior.cleanup --cachenow escalates throughsudo:dnf clean allclears the root-owned package cache.
6.2.0(2026-03-25)Add
--quietoption to all invocations to reduce log verbosity.
5.20.0(2024-11-25)Add support for new
dnf5manager. Refs #1423.