The immediate context is my need to upgrade pathauto which was diagnosed as having an XSS vulnerability.

Now, should I just overwrite the old module in my 4.7 install with the new one? Should I then run update.php and choose pathauto from the list of modules and do something? It's the latter part that is not clear from the handbook pages on upgrading.

Funnily enough, if the security advisory had provided a patch file, I could have done this in seconds. I can't help laughing thinking about this and remembering the time I used to balk at patch files;-)