Most apt-get disasters start with someone pressing Enter on a plan they never read. This guide gives you a repeatable apt-get routine: check where packages come from, refresh the indexes, preview the change, apply it, and remove or restore it when needed. Allow 10 to 20 minutes for a normal package change, plus download time.
The commands match APT 2.8.3 on Ubuntu 24.04.
apt package installed and a network connection for repository operations.curl is not the same as a downloaded filename such as curl_8.5.0-2ubuntu10_amd64.deb. If you are unsure, search the local cache first:apt-cache policy curl
apt-cache search '^curl$'
Warning: do not paste a package name or repository line from an untrusted source without checking it. APT can authenticate repository metadata, but you still choose which repositories and packages your machine trusts.
APT reads the traditional /etc/apt/sources.list file and active files in /etc/apt/sources.list.d/.
.list file uses one-line entries..sources file uses deb822 stanzas separated by blank lines.grep -R --no-filename -E '^[[:space:]]*(deb|deb-src|Types:|URIs:|Suites:|Components:|Signed-By:)' \
/etc/apt/sources.list /etc/apt/sources.list.d 2>/dev/null
A one-line entry has the shape deb [options] URI suite components. For example, deb [signed-by=/etc/apt/keyrings/vendor.gpg] https://packages.example.invalid stable main names a binary package source and restricts its signing key. In deb822 form, the same concepts are fields:
Types: deb
URIs: https://packages.example.invalid
Suites: stable
Components: main
Signed-By: /etc/apt/keyrings/vendor.gpg
Use a real vendor URI and keyring path only after verifying them from that vendor's documentation. Prefer https where it is available. The Signed-By path must be absolute and readable by APT's _apt user.
Warning: do not work around a signature error with trusted=yes or an insecure-source option. Those settings weaken repository authentication.
Checkpoint: you know which source file provides the package and can identify its suite, components and signing key. If this is not clear, stop before running an install command.
apt-get update downloads and scans the indexes named by the configured sources. It does not upgrade installed packages. Run it before an upgrade or install when the package information may be stale.
sudo apt-get update
Expected output includes lines such as Hit:, Get:, and a final package-list summary. Warnings deserve attention: missing signatures, an expired repository, a suite that does not exist, or a source that was ignored. Do not carry on just because some other repositories succeeded.
apt-cache policy curl
Check that the candidate version and repository shown by apt-cache policy are what you intended. A source entry can change the candidate APT selects, and a machine can have several sources for the same package.
Use -s (also --simulate or --dry-run) before any operation that installs, upgrades or removes packages. The simulation prints the planned actions without changing the system. APT notes that simulation does not take the real package lock, so it is not a substitute for checking the live result at the confirmation prompt.
apt-get -s install curl
apt-get -s --no-remove install curl
Look for the NEW, REMOVE, Upgrade and NOT upgraded lines. The second command asks APT not to remove packages; if the requested change needs a removal, it should fail rather than quietly making one. Review the package list, especially when the operation touches a service, a kernel, a desktop environment or a library used by several applications.
For a single installed package, this is a useful narrower preview:
apt-get -s install --only-upgrade curl
--only-upgrade stops APT installing a package that is not already installed. --reinstall has the opposite purpose: the package is installed but its files need replacing:
apt-get -s --reinstall install curl
Checkpoint: the simulation names only the packages and dependency changes you expect. If it proposes removals or a large unrelated upgrade, investigate the source priorities and dependency chain before proceeding.
Install one or more package names with install. The command also upgrades named packages when a newer candidate exists, and it may install their dependencies.
sudo apt-get install curl ca-certificates
Read the final confirmation prompt. For unattended use, -y or --assume-yes answers yes to prompts, but it does not make a risky plan safe. Combine it only with a reviewed plan and a controlled environment.
Warning: avoid --force-yes. The manual marks that option as deprecated, and it can force unsafe choices.
To upgrade all currently installed packages without removing packages or installing new ones, use:
sudo apt-get update
apt-get -s upgrade
sudo apt-get upgrade
upgrade holds packages back when changing them would alter the install state of another package. dist-upgrade resolves changing dependencies more broadly and may remove packages, so treat it as a planned maintenance operation:
apt-get -s dist-upgrade
sudo apt-get dist-upgrade
Warning: never use dist-upgrade merely because a routine upgrade leaves packages back. Inspect the simulation first and confirm that removals and service restarts are acceptable.
Removing a package leaves its configuration files. Purging removes those too.
apt-get -s remove example-package
sudo apt-get remove example-package
apt-get -s purge example-package
sudo apt-get purge example-package
Warning: these actions are destructive to installed software and, with purge, to configuration. Back up important configuration before confirming.
APT does not provide a general undo transaction. Recovery normally means reinstalling the package, restoring your configuration backup, and checking the service:
sudo apt-get install example-package
sudo systemctl status example-service
For packages installed automatically as dependencies and no longer needed, preview autoremove carefully. It can remove more than the package you have just been thinking about.
apt-get -s autoremove
sudo apt-get autoremove
APT also supports an explicit package version, such as example-package=1.2.3-4, or a release selector such as example-package/stable. Both forms can downgrade a package. Confirm the candidate with apt-cache policy first, and do not use a version copied from an unrelated distribution.
Downloaded package archives normally live under /var/cache/apt/archives/. clean removes all retrieved package files there, while autoclean removes only files that can no longer be downloaded. Neither command removes installed packages.
sudo apt-get autoclean
sudo apt-get clean
Prefer autoclean when you only want to trim stale cache contents. After clean, a later reinstall may need to download the package again. If package management reports broken dependencies, use the diagnostic command first:
apt-get check
It updates the package cache and checks for broken dependencies.
Tip: do not jump straight to a repair command from a forum post. Keep the error output, inspect the proposed simulation, and work out which interrupted operation caused the problem.
apt-get update completed without unexplained repository errors.apt-cache policy, dpkg -s or systemctl status confirms it.