--- # Restrict to security-origin updates only (not a full dist-upgrade). unattended_upgrades_security_only: true # Extra Origins-Pattern lines appended verbatim, for when # unattended_upgrades_security_only is turned off later (e.g. to also allow # the "-updates" pocket). Left empty by default. unattended_upgrades_origins_extra: [] # Reboot handling. Off by default would mean patches needing a reboot never # take effect until someone reboots manually; scheduled means an automatic # reboot at a fixed, low-traffic time on the days it's actually needed. unattended_upgrades_auto_reboot: true unattended_upgrades_auto_reboot_time: "03:00" unattended_upgrades_remove_unused_deps: true # Set to a mail address (and ensure a working mail transport is configured # on the host) to get notified on failure. Empty disables mail entirely. unattended_upgrades_mail_to: "" unattended_upgrades_mail_on_only_error: true