How to Use DNF on Rocky Linux: Packages, Repositories, and Updates
DNF (Dandified YUM) is the default tool on Rocky Linux for searching, installing, updating, and removing packages, as well as managing transaction history. Before executing a command, it is important to check the target package and the list of dependency changes, and on production servers, to clarify the repository and update scope before applying changes.
DNF Version and Basic Format
Since the DNF implementation and output format may differ depending on the Rocky Linux version, first check the version. The typical command format is dnf [options] command [target].
dnf --version dnf --help
Query commands can be run as a regular user, but installing, removing, or updating packages that change the system requires administrator privileges.
Searching for Packages and Checking Information
Searching by Name and Description
dnf search nginx dnf info nginx
search searches in the name and description, and info shows version, architecture, repository, and description. If there are multiple versions or architectures with the same name, check the results carefully.
Finding Packages That Provide Files or Commands
dnf provides '*/semanage' dnf provides /usr/bin/rsync
If you do not know the exact path, you can use a wildcard. It is safer to enclose the pattern in quotes so that it is not expanded by the shell first.
Installing and Reinstalling Packages
sudo dnf install nginx sudo dnf reinstall nginx
install resolves the required dependencies along with the package. reinstall reinstalls the same version if the package file is corrupted, but it is not a command that forcibly resets configuration files modified by the administrator.
Local RPM files can also be installed with DNF to resolve dependencies from the repository.
sudo dnf install ./example-package.rpm
Checking and Applying Updates
Querying Updatable Items
dnf check-update dnf updateinfo list
dnf check-update can return exit code 100 if updates are available. If a shell script does not distinguish this from a normal error code, it may mistakenly interpret the normal "updates available" state as a failure.
Updating All or Specific Packages
sudo dnf upgrade sudo dnf upgrade openssl
Kernel, C library, and core service updates may require a reboot or service restart. In production environments, prepare the change details, maintenance time, and rollback methods in advance.
Package removal and cleaning up unnecessary dependencies
sudo dnf remove nginx sudo dnf autoremove --assumeno
remove can suggest not only the target package but also dependency packages that are no longer deemed necessary. Be sure to read the deletion list on the confirmation screen. autoremove --assumeno is useful for reviewing cleanup candidates without actually deleting them.
Managing installation lists and repositories
Viewing package lists
dnf list --installed dnf list --available dnf list --upgrades
Checking repository status
dnf repolist dnf repolist --all dnf repository-packages appstream list --available
When enabling additional repositories, you should verify the provider, signing key, support scope, and the potential to replace packages from the default repositories. For troubleshooting, you can choose to exclude or enable a specific repository just once.
sudo dnf --disablerepo='example-repo' upgrade sudo dnf --enablerepo='example-repo' install package-name
Checking transaction history and reviewing rollback
dnf history dnf history info transaction_ID sudo dnf history undo transaction_ID
`history undo` may fail if the repository no longer provides the required previous version or if dependencies have changed after the transaction. It is not a backup function that restores databases, configurations, or application data, so you need to prepare a separate operational rollback method.
Cache and Metadata Management
| Command | Purpose |
|---|---|
dnf makecache |
Pre-downloads metadata from an active repository. |
dnf clean metadata |
Deletes stored repository metadata. |
dnf clean packages |
Deletes package files remaining in the cache. |
dnf clean all |
Cleans the DNF cache, including metadata and packages. |
There is no need to habitually run `clean all` every time a repository error occurs. First, checking the network, system time, repository URL, and GPG signature error messages helps in identifying the cause.
Summary of Frequently Used Commands
| Purpose | Command |
|---|---|
| Search | dnf search keyword |
| Check Information | dnf info package_name |
| Install | sudo dnf install package_name |
| Update | sudo dnf upgrade |
| Delete | sudo dnf remove package-name |
| File providing package | dnf provides '*/filename' |
| Transaction history | dnf history |
| Repository list | dnf repolist --all |
How to operate safely
- Before using the automatic confirmation option, a person first reviews the installation/removal list suggested by DNF.
- For important servers, back up data and settings before updating and test the recovery procedure.
- Verify the source of repository files and GPG keys, and do not keep unnecessary external repositories constantly enabled.
- Multiple servers reduce version differences by using the same repository snapshots or verified automated procedures.
Reference Documents
Detailed options and exit statuses for each command can be found in the DNF official command reference documentation.









