Fedora YUM

Note

The standalone yum project is archived; on modern RHEL and Fedora the yum command is a maintained compatibility alias for dnf.

ID

yum

Links

Home page · Documentation · Repository · Wikipedia

Upstream stars

⭐ 135

Last commit

2021-04-02

Version requirement

>= 4

Platforms

🅱️ BSD · 🐧 Linux · ⨂ Unix

Operations

installed · outdated · orphans · search · install · upgrade · upgrade_all · remove · sync · cleanup · doctor

purl types

pkg:rpm/ · pkg:yum/

CLI name

yum

Every call

yum --color=never --quiet <command>

Issues and PRs

📦 manager: rpm-based

Source

dnf.py

YUM, the package manager DNF superseded.

On current Fedora and RHEL the yum binary is a wrapper around dnf. mpm drives it exactly as DNF, only the binary name differs.

What mpm adds to yum

Through mpm, yum gains --exact and --extended search, to narrow to exact names or match descriptions.

Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover yum alongside dnf, dnf5, microdnf, urpmi, zypper and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your yum commands, in mpm

You already know yum: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With yum

With mpm

List what’s installed

dnf repoquery --userinstalled --qf <format>

mpm --yum installed

List outdated packages

dnf repoquery --installed --qf <format>

mpm --yum outdated

Search for a package

dnf4 search usd

mpm --yum search usd

Install a package

sudo dnf --assumeyes install pip

mpm install pkg:yum/pip

Upgrade one package

sudo dnf --assumeyes upgrade pip

mpm --yum upgrade pip

Upgrade everything

sudo dnf --assumeyes upgrade

mpm --yum upgrade --all

Remove a package

sudo dnf --assumeyes remove pip

mpm remove pkg:yum/pip

List orphaned dependencies

dnf repoquery --unneeded

mpm --yum orphans

Clear caches

sudo dnf clean all

mpm --yum cleanup --cache

Run health checks

dnf check

mpm --yum doctor

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

outdated

✅

orphans

✅

search

✅

Matches names only, with no exact or extended mode. Exact and extended search backfilled by mpm.

install

✅

A package already installed as a dependency is marked explicit by mpm.

upgrade

✅

upgrade_all

✅

remove

✅

Removing a package also drops the dependencies it leaves orphaned, since remove runs autoremove. The --orphans flag also drops the package’s orphaned dependencies.

sync

✅

cleanup

✅

The --orphans flag runs the system-wide orphan sweep.

doctor

✅

Configuration

  • Ignore yum on the mpm CLI by passing the --no-yum option.

  • Ignore it for every run in your configuration:

    [mpm]
    yum = false
    
  • Raise the timeout of all yum calls:

    [mpm.overrides.yum]
    timeout = 900
    
  • Run mpm config-template yum to print all overridable settings for your configuration file:

    [mpm.overrides.yum]
    cli_names = [
        "yum",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = []
    pre_args = [
        "--color=never",
        "--quiet",
    ]
    pre_cmds = []
    requirement = ">=4.0.0"
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "dnf5\\s+version\\s+(?P<version>\\S+)",
        "(?P<version>\\S+)",
    ]
    

The arguments and environment variables listed in the box atop this page are forced on every yum call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.

Recipes

A few jobs you would otherwise script around yum, one mpm command each:

  • Snapshot and clone a machine: mpm --yum dump yum.toml, then mpm restore yum.toml on the next one.

  • Export a compliance SBOM: mpm --yum sbom (CycloneDX by default, --spdx for SPDX).

  • Gate CI on health: mpm --yum doctor relays Fedora YUM’s own diagnosis and exits non-zero on trouble.

Privilege escalation

System-wide manager: mpm wraps its privileged operations in sudo out of the box. Instead of letting the tool prompt mid-run, mpm primes the credential cache up-front, with a single branded password prompt at most. Turn escalation off for rootless setups with --no-sudo or the per-manager sudo override.

Its privileged operations are cleanup, install, remove, upgrade, upgrade_all.

See privilege escalation for the full policy.

Concurrency

mpm never runs yum at the same time as dnf, dnf5, microdnf, urpmi or zypper: they all reach the RPM database, where a second writer either waits for the first one to finish or fails on its lock. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.

Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.

Cooldown

State of Fedora YUM’s release-age gating, from the cooldown support table:

Status: ➖ N/A (deprecated alias for dnf on RHEL-family)

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: Distro binary archives (pkg:deb, pkg:rpm, pkg:alpm, pkg:apk)

  • Retraction: Index revert: removal is an archive operation and the mirror is rebuilt without the package. Debian, for one, requires filing an RM: bug against ftp.debian.org (developers-reference)

  • Publish date: ❌ the version string is the distro maintainer’s build, carrying no upstream publication date

With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.

Version check

The version is extracted from the output of yum --version with the first of these regular expressions to match:

r"dnf5\s+version\s+(?P<version>\S+)"
r"(?P<version>\S+)"

Upstream project

Metrics

rpm-software-management/yum

Activity

commit activity open issues open pull requests

Popularity

forks watchers contributors

Metadata

license main language

Changelog

  • 8.0.0 (2026-09-20)

    • Mark a package already installed as a dependency as explicitly installed when mpm install or mpm restore names it, so mpm cleanup --orphans keeps it.

    • Fix version detection against dnf5, whose banner was read as the version dnf5, dropping every RPM front-end from the pool on Fedora 41 and later.

    • Fix search on dnf5, which returned no results at all, and outdated, which reported the upgrade candidate’s own version as the installed one.

  • 7.4.0 (2026-07-25)

    • Plain cleanup no longer removes orphaned packages: their native sweeps moved behind cleanup --orphans. This also stops emerge’s cleanup from triggering its pre-depclean world upgrade unless --orphans is given.

    • remove no longer cascades to orphaned dependencies by default: a plain removal keeps them. Use the new remove --orphans to restore the previous behavior.

  • 6.2.0 (2026-03-25)

    • Add --quiet option to all invocations to reduce log verbosity.

  • 5.19.0 (2024-11-14)

    • Implement remove operation.

    • Use query template instead of regex parsing to retrieve package data.

  • 5.0.0 (2022-04-25)

    • Add dedicated yum package manager. Refs #415.

  • 4.12.0 (2022-04-04)

    • Allow yum to act as dnf. Closes #415.