Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Stop YUM from Upgrading Certain Packages on CentOS

This guide shows how to keep chosen software at its current version when you update your CentOS server. It needs root access, so it fits a VPS or dedicated server.

How-To Guides2 min read10 steps

What are YUM and RPM?

An RPM is a software package, like an app installer. YUM is the tool that installs and updates RPMs on CentOS. When you run yum update, it upgrades everything. Sometimes that is a problem. A new PHP version may break your website, for example. So you tell YUM to leave some packages alone.

Tip: CentOS is old software now. Newer systems such as AlmaLinux and Rocky use dnf, and the steps are very similar.

Method 1: Exclude a package in yum.conf

Warning: held packages will not get security fixes. Remove the hold when you are ready to update. Back up the file first.

  1. Log in to your server as root with SSH.
  2. Back up the settings file:
cp /etc/yum.conf /etc/yum.conf.bak
  1. Open the file in an editor:
nano /etc/yum.conf
  1. Under the [main] section, add a line:
exclude=php* kernel*

The star means "anything that starts with this". This line blocks all PHP and kernel packages from updating.

  1. Save and close the file. In nano, press Ctrl + O, Enter, then Ctrl + X.
  2. Run an update. Held packages are skipped:
yum update

Method 2: Skip a package for one run

You can block packages only for a single update:

yum update --exclude=php*

This leaves PHP alone this one time. The next plain yum update will upgrade it.

Method 3: Use the versionlock plugin

This locks an exact version.

  1. Install the plugin:
yum install yum-plugin-versionlock
  1. Lock a package:
yum versionlock add httpd
  1. See the list of locks:
yum versionlock list
  1. Remove all locks when you are ready:
yum versionlock clear

Quick recap

  • YUM updates every package by default.
  • Use exclude= in /etc/yum.conf to hold packages.
  • Use --exclude for a single run.
  • Use versionlock to pin an exact version.
  • Remember to remove holds so you still get security fixes.