DNF Guide (Fedora/RHEL)
DNF is the package manager for the Red Hat family of Linux distributions: Fedora, RHEL, AlmaLinux, Rocky Linux, and CentOS Stream. It replaced the older YUM command and brought significant improvements in dependency resolution speed and transaction management. This guide covers the full toolkit from daily commands through module streams, COPR repositories, version locking, and the RPM layer underneath.
Daily workflow
# Refresh metadata and upgrade all installed packages
sudo dnf upgrade --refresh
# Just upgrade without forcing a metadata refresh
sudo dnf upgrade
# Check for available upgrades without installing
dnf check-update
# See what would change before committing
dnf upgrade --dry-run
--refresh forces DNF to re-download the package metadata from all repos before checking for upgrades. Without it, DNF uses cached metadata that may be up to a few hours old. On interactive machines, using --refresh for manual upgrades is a good habit.
Installing and removing packages
# Install a package
sudo dnf install nginx
# Install multiple packages at once
sudo dnf install nginx postgresql redis
# Install a specific version
sudo dnf install nginx-1.24.0-1.fc40
# Install a package and all its weak dependencies
sudo dnf install --allowerasing nginx
# Reinstall a package (useful if files were accidentally deleted)
sudo dnf reinstall nginx
# Remove a package
sudo dnf remove nginx
# Remove a package and anything that depends on it
sudo dnf autoremove nginx
# Remove packages that are no longer required by anything installed
sudo dnf autoremove
Unlike apt purge, DNF’s remove cleans up configuration files by default for most packages. The autoremove command handles orphaned dependencies.
Searching and inspecting packages
# Search by name or summary
dnf search nginx
dnf search "web server"
# Full-text search including descriptions
dnf search --all nginx
# Show detailed package information
dnf info nginx
# Show all available versions of a package across repos
dnf repoquery --available nginx
# Find which package provides a file or command
dnf provides /usr/sbin/nginx
dnf provides "*/nginx"
# List files installed by a package
dnf repoquery --installed --list nginx
rpm -ql nginx # equivalent RPM query
# Show reverse dependencies (what depends on a package)
dnf repoquery --whatrequires nginx
# List all installed packages
dnf list installed
# List packages with available upgrades
dnf list updates
# Check if a specific package is installed
dnf list installed nginx
rpm -q nginx # RPM equivalent
DNF history and rollback
One of DNF’s advantages over apt is built-in transaction history with rollback capability:
# See a list of all past transactions
dnf history
# Show details of a specific transaction
dnf history info 42
# Undo a specific transaction (rolls back an install or upgrade)
sudo dnf history undo 42
# Redo a previously undone transaction
sudo dnf history redo 42
# Roll back the system to the state it was in before transaction 42
sudo dnf history rollback 42
Transaction IDs are listed in the left column of dnf history output. Rollback is most useful after an upgrade breaks something: you can undo the entire upgrade transaction and restore the previous package versions.
Version locking
# Install the versionlock plugin (usually pre-installed on Fedora)
sudo dnf install python3-dnf-plugins-core
# Lock a package at its current version
sudo dnf versionlock add nginx
# Lock a specific version
sudo dnf versionlock add nginx-1.24.0-1.fc40
# List all locked packages
dnf versionlock list
# Remove a lock
sudo dnf versionlock delete nginx
# Clear all locks
sudo dnf versionlock clear
Version-locked packages are skipped during dnf upgrade. They appear in the output as excluded. Locking is useful for packages where a new version breaks your application, or where you need to stay at a specific version for compatibility reasons.
Repository management
# List all configured repositories
dnf repolist
# List all repos including disabled ones
dnf repolist --all
# Show detailed repo information
dnf repoinfo fedora-updates
# Enable or disable a repository for one command
sudo dnf install --enablerepo=updates-testing some-package
sudo dnf upgrade --disablerepo=rpmfusion-nonfree
# Enable or disable a repository permanently
sudo dnf config-manager --enable repo-id
sudo dnf config-manager --disable repo-id
# Repo configuration files live here
ls /etc/yum.repos.d/
A .repo file looks like this:
[fedora]
name=Fedora $releasever - $basearch
metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-$releasever&arch=$basearch
enabled=1
countme=1
metadata_expire=6h
repo_gpgcheck=0
type=rpm
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
The gpgcheck=1 line ensures DNF verifies the signature of every downloaded package. Never disable this in production.
Adding third-party repositories
# RPM Fusion (media codecs, proprietary drivers) -- the most common third-party repo
sudo dnf install \
https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm \
https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm
# Verify the repo was added
dnf repolist
# Import a GPG key for a repo
sudo rpm --import https://example.com/RPM-GPG-KEY-example
# Add a repo directly from a URL
sudo dnf config-manager --add-repo https://example.com/repo.repo
COPR repositories
COPR (Cool Other Package Repos) is Fedora’s community repository system, roughly equivalent to Ubuntu’s PPAs. Anyone can host a COPR repository with packages not in the official Fedora repos.
# Install the COPR plugin (usually pre-installed)
sudo dnf install dnf-plugins-core
# Enable a COPR repository
sudo dnf copr enable username/reponame
# Install from COPR
sudo dnf install some-package
# Disable a COPR repo
sudo dnf copr disable username/reponame
# List enabled COPR repos
dnf copr list
# Search COPR for a package
dnf copr search somepackage
COPR packages are community-maintained and not vetted by Fedora. Use only repos from maintainers you trust.
DNF modules (Application Streams)
Modules let you install different versions of the same software from the same repository. They are most prominent on RHEL and its clones, where Application Streams provide newer software without requiring an OS upgrade.
# List available modules
dnf module list
# List modules for a specific package
dnf module list nodejs
# Show module details including available streams and profiles
dnf module info nodejs
# Enable a specific module stream
sudo dnf module enable nodejs:20
# Install the default profile of a module
sudo dnf module install nodejs
# Install a specific profile
sudo dnf module install nodejs:20/default
# Reset a module to its default state
sudo dnf module reset nodejs
# Disable a module stream
sudo dnf module disable nodejs:20
A module stream is a version (e.g., nodejs:20). A profile is a set of packages within that stream (e.g., default, development, minimal). Enabling a stream makes it available; installing a profile pulls in the actual packages.
Group installs
DNF can install predefined groups of related packages:
# List available groups
dnf group list
# Show what a group contains
dnf group info "Development Tools"
# Install a group
sudo dnf group install "Development Tools"
# Remove a group
sudo dnf group remove "Development Tools"
# Install minimal group (only mandatory packages)
sudo dnf group install --with-optional "Development Tools"
Groups are useful for setting up a development environment or a server role without having to know every individual package name.
Cache and cleanup
# Remove cached package data
sudo dnf clean packages
# Remove cached metadata
sudo dnf clean metadata
# Remove everything from the cache
sudo dnf clean all
# Show how much cache is on disk
du -sh /var/cache/dnf/
# Remove packages no longer in any repo
sudo dnf clean dbcache
# Remove old kernels (keeps the 3 most recent by default)
sudo dnf remove --oldinstallonly --setopt=installonly_limit=3 kernel
On Fedora, old kernels are cleaned up automatically. On RHEL systems, you may need to set installonly_limit=3 in /etc/dnf/dnf.conf to prevent accumulation.
The RPM layer
rpm is the low-level tool DNF uses internally. You need it directly for inspecting .rpm files before installing, querying the package database, and verifying package integrity.
# Install a local .rpm file
sudo rpm -i package.rpm
# Install with dependency checking (use dnf instead for better dep resolution)
sudo dnf install ./package.rpm
# Query package information (not installed)
rpm -qip package.rpm # info
rpm -qlp package.rpm # file list
# Query installed packages
rpm -qa # list all installed packages
rpm -qi nginx # info about an installed package
rpm -ql nginx # files installed by nginx
rpm -qc nginx # config files installed by nginx
rpm -qd nginx # documentation files installed by nginx
rpm -qs nginx # state of files installed by nginx
# Find which package owns a file
rpm -qf /usr/sbin/nginx
# Verify package integrity
rpm -V nginx # check against recorded checksums
rpm -Va # verify all installed packages
# Import a GPG key
sudo rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-40-x86_64
# Check all installed GPG keys
rpm -q gpg-pubkey --qf '%{name}-%{version}-%{release} --> %{summary}\n'
When dnf install fails on a local .rpm due to missing dependencies, use sudo dnf install ./package.rpm instead of rpm -i. DNF resolves the dependencies; rpm does not.
Automatic updates
On Fedora Workstation, dnf-automatic can apply updates automatically. On servers, it is commonly used for security updates only:
# Install dnf-automatic
sudo dnf install dnf-automatic
# Configuration
sudo nano /etc/dnf/automatic.conf
# Key settings in automatic.conf:
# upgrade_type = security # only security updates
# upgrade_type = default # all updates
# apply_updates = yes # actually install (not just download)
# emit_via = email # notification method
# Enable and start the timer
sudo systemctl enable --now dnf-automatic.timer
# Check when it will next run
systemctl status dnf-automatic.timer
For servers, setting upgrade_type = security and apply_updates = yes keeps the system patched without risking application breakage from feature updates.
Quick reference
# Daily workflow
sudo dnf upgrade --refresh
# Install / remove
sudo dnf install pkg
sudo dnf remove pkg
sudo dnf autoremove
# Search and inspect
dnf search term
dnf info pkg
dnf provides /path/to/file
# Version management
sudo dnf versionlock add pkg
sudo dnf versionlock delete pkg
dnf versionlock list
# Repository management
dnf repolist
sudo dnf copr enable user/repo
sudo dnf config-manager --add-repo URL
# Modules (RHEL/Fedora)
dnf module list
sudo dnf module enable name:stream
sudo dnf module install name:stream/profile
# History and rollback
dnf history
sudo dnf history undo ID
# RPM layer
rpm -qf /path/to/file # who owns this file?
rpm -ql packagename # what files did this install?
rpm -V packagename # are the files intact?
# Cleanup
sudo dnf clean all
sudo dnf autoremove
DNF’s transaction history and rollback capability make it one of the more recoverable package managers available on Linux. Pair that with COPR for community packages and modules for version management, and Fedora’s package ecosystem is well-equipped for both desktop and server use.
Frequently Asked Questions
What is DNF in Linux?
DNF (Dandified YUM) is the package manager for Fedora, RHEL, AlmaLinux, Rocky Linux, and CentOS Stream. It replaced the older YUM (Yellowdog Updater Modified) starting with Fedora 18. DNF handles downloading, installing, upgrading, and removing RPM packages from configured repositories, with automatic dependency resolution and GPG signature verification.
What is the difference between dnf update and dnf upgrade?
On modern DNF versions, dnf update and dnf upgrade are aliases that do the same thing: upgrade all installed packages to their latest available versions, including removing obsolete packages. This is unlike the historical YUM distinction where update kept old versions installed alongside new ones. Either command works; dnf upgrade is more explicit about what is happening.
How do I add a repository in DNF?
You can add a repository by placing a .repo file in /etc/yum.repos.d/, by installing a release RPM that configures the repo automatically, or with the dnf config-manager —add-repo URL command. For Fedora community repos, dnf copr enable username/reponame adds a COPR (Community Projects) repository. Always verify the source before adding third-party repositories.
What are DNF modules?
DNF modules (also called Application Streams on RHEL) let you install different versions of the same software from the same repository. For example, you might have module streams for Python 3.9, 3.11, and 3.12 available simultaneously, and you select which stream to enable. This allows the OS to ship the latest features for some software while keeping older stable versions available for compatibility.
How do I prevent a package from being upgraded with DNF?
Use dnf versionlock add packagename to lock a package at its current version. This requires the dnf-plugins-core package, which is installed by default on Fedora. To remove the lock, use dnf versionlock delete packagename. You can also exclude packages in /etc/dnf/dnf.conf by adding an excludepkgs= line, though versionlock is more flexible.