# unattended_upgrades Installs and configures `unattended-upgrades` for automatic security patching, separate from `update-packages.yml` (which handles deliberate, scheduled full-package updates — see the repo README). Security-only by default. Reboots when required, at a fixed scheduled time (default 03:00), rather than never or immediately — see `defaults/main.yml` to change this. Mail-on-failure is supported but disabled by default since no mail transport is configured on these hosts yet.