Anubhav<p>About last week I had set up "automatic timer" (after installing <a href="https://hachyderm.io/tags/dnf" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>dnf</span></a>-automatic package & updating /etc/dnf/automatic*) to update the packages with <a href="https://hachyderm.io/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> fixes on <a href="https://hachyderm.io/tags/RockyLinux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RockyLinux</span></a> 8. That failed to update freetype v2.9 package due to CVE-2025-27363 <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27363" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">nvd.nist.gov/vuln/detail/CVE-2</span><span class="invisible">025-27363</span></a> ; so did fail dnf upgrade --security💩 (update was included in unqualified dnf upgrade).</p><p>Utterly useless option & package. Removed the timer & dnf-automatic package.</p><p>This -- failure of dnf upgrade --security to update vulnerable packages -- had happened a second time (yes, I had forgotten the uselessness of it; a timely reminder it was). I will need to stick to update-all-the-packages.<br> <br><a href="https://hachyderm.io/tags/CentOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CentOS</span></a> <a href="https://hachyderm.io/tags/sysAdmin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sysAdmin</span></a> <a href="https://hachyderm.io/tags/systemAdministration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>systemAdministration</span></a></p>