OS Update Checker
Read-only, cross-platform package update checker. Auto-detects the available package manager, lists upgradable packages, fetches changelogs, and classifies risk (security, moderate, low). Designed to give enough context to approve or defer an upgrade confidently.
Supported Package Managers
| OS |
Package Manager |
| Debian / Ubuntu / Mint |
apt |
| Fedora / RHEL 8+ / Rocky / Alma |
dnf |
| CentOS 7 / RHEL 7 |
yum |
| Arch / Manjaro / EndeavourOS |
pacman / checkupdates |
| openSUSE Leap / Tumbleweed / SLES |
zypper |
| Alpine Linux |
apk |
| macOS / Linux (Homebrew) |
brew |
Usage
# Human-readable summary with changelogs (auto-detects OS)
python3 scripts/check_updates.py
# JSON output (for dashboards, cron, integrations)
python3 scripts/check_updates.py --format json
# Skip changelogs for a quick count
python3 scripts/check_updates.py --no-changelog
Risk Classification
- 🔴 security — source repo contains a security indicator
- 🟡 moderate — critical package (kernel, openssh, openssl, sudo, curl, bash, etc.)
- 🟢 low — standard maintenance update
How It Works
- Detects available package manager from PATH (
apt → dnf → yum → pacman → zypper → apk → brew)
- Lists upgradable packages using the appropriate read-only command
- Validates each package name against a per-backend allowlist regex before any further use
- Fetches the most recent changelog entry per package (apt:
apt changelog; dnf/yum: rpm --changelog; others: package info)
- Reports in text or JSON format
Security Design
subprocess is used exclusively with shell=False — arguments are passed as a list, never interpolated into a shell string
- Package names are validated against per-backend allowlist patterns before use in commands
- All exceptions are caught by specific type — no bare
except
- Read-only commands only — no installs, no writes, no service restarts
System Access
- Commands (read-only):
apt list, apt changelog, dnf check-update, rpm -q --changelog, yum check-update, pacman -Qu, pacman -Si, zypper list-updates, zypper info, apk list, apk info, brew outdated, brew info
- Network: Outbound HTTPS to distribution changelog servers (apt only; others use local package metadata)
- No file writes
Requirements
- Python 3.10+
- One supported package manager available on PATH
1---2name: os-update-checker3description: Check for available OS package updates with per-package changelog summaries and risk classification. Supports apt (Debian/Ubuntu), dnf (Fedora/RHEL), yum (CentOS 7), pacman (Arch), zypper (openSUSE), apk (Alpine), and brew (macOS). Use when: checking system update status, before approving upgrades, or in heartbeats/cron for periodic OS health monitoring. Read-only — does not install or modify anything.4---56# OS Update Checker78Read-only, cross-platform package update checker. Auto-detects the available package manager, lists upgradable packages, fetches changelogs, and classifies risk (security, moderate, low). Designed to give enough context to approve or defer an upgrade confidently.910## Supported Package Managers1112| OS | Package Manager |13|---|---|14| Debian / Ubuntu / Mint | `apt` |15| Fedora / RHEL 8+ / Rocky / Alma | `dnf` |16| CentOS 7 / RHEL 7 | `yum` |17| Arch / Manjaro / EndeavourOS | `pacman` / `checkupdates` |18| openSUSE Leap / Tumbleweed / SLES | `zypper` |19| Alpine Linux | `apk` |20| macOS / Linux (Homebrew) | `brew` |2122## Usage2324```bash25# Human-readable summary with changelogs (auto-detects OS)26python3 scripts/check_updates.py2728# JSON output (for dashboards, cron, integrations)29python3 scripts/check_updates.py --format json3031# Skip changelogs for a quick count32python3 scripts/check_updates.py --no-changelog33```3435## Risk Classification3637- 🔴 **security** — source repo contains a security indicator38- 🟡 **moderate** — critical package (kernel, openssh, openssl, sudo, curl, bash, etc.)39- 🟢 **low** — standard maintenance update4041## How It Works42431. **Detects** available package manager from PATH (`apt` → `dnf` → `yum` → `pacman` → `zypper` → `apk` → `brew`)442. **Lists** upgradable packages using the appropriate read-only command453. **Validates** each package name against a per-backend allowlist regex before any further use464. **Fetches** the most recent changelog entry per package (apt: `apt changelog`; dnf/yum: `rpm --changelog`; others: package info)475. **Reports** in text or JSON format4849## Security Design5051- `subprocess` is used exclusively with `shell=False` — arguments are passed as a list, never interpolated into a shell string52- Package names are validated against per-backend allowlist patterns before use in commands53- All exceptions are caught by specific type — no bare `except`54- Read-only commands only — no installs, no writes, no service restarts5556## System Access5758- **Commands (read-only):** `apt list`, `apt changelog`, `dnf check-update`, `rpm -q --changelog`, `yum check-update`, `pacman -Qu`, `pacman -Si`, `zypper list-updates`, `zypper info`, `apk list`, `apk info`, `brew outdated`, `brew info`59- **Network:** Outbound HTTPS to distribution changelog servers (apt only; others use local package metadata)60- **No file writes**6162## Requirements6364- Python 3.10+65- One supported package manager available on PATH