title: Pending Updates: Pending Package/System Updates
agents: linux, windows
catalog: os/misc
license: GPLv2
distribution: check_mk
description:
 Detects pending updates across every supported backend found on the monitored host:
 {apt} (Debian/Ubuntu), {dnf}/{yum} (RHEL family), {zypper} (openSUSE/SLES), {apk}
 (Alpine) on Linux, plus Windows Update and {winget} on Windows. Classifies each
 update as {security} or {normal} where the backend provides native advisory data
 ({apt}, {dnf}/{yum}, {zypper} patches, Windows Update); {apk}, {winget} and
 {zypper} updates not covered by any patch (e.g. on Tumbleweed) have no such native
 signal and are classified {unknown} rather than guessed. Package manager output is
 always parsed untranslated, independent of the host's system language.

 Updates matching a configured regular expression (checked against the package name
 and any advisory IDs, using a substring/infix search) are counted separately as
 {ignored} rather than dropped. Packages natively held/pinned by the package manager
 itself ({apt-mark hold}, {dnf versionlock}, {zypper addlock}) are counted separately
 as {held} and shown directly in the service summary. Windows-only optional updates
 (drivers etc., opt-in via the Bakery rule) are counted separately as {optional}.
 None of {ignored}/{held}/{optional} count towards the security/normal/unknown
 thresholds, but all stay visible in the service summary or details.

 This check goes {CRIT}ical or {WARN}ing based on the number of pending security,
 normal, and held updates, configurable separately via the check's parameters --
 security updates default to {CRIT} starting at the very first one.

 The per-package "Normal updates:" listing in the service details can be turned
 off via the check's parameters (shown by default) on a host with many routine,
 non-security updates pending -- this only hides that listing, the Normal
 count/metric/threshold above are unaffected.

 Named "Pending Updates", not "System Updates": Checkmk's own built-in
 {windows_updates} check already uses service name "System Updates", which
 collided with this plug-in's original name on any host running both.

item:
 None, this is a single service per host.

discovery:
 One service is created per host that reports a {system_updates} agent section.
