Comment by superkuh

15 hours ago

For the past week I assumed my old Debian 11 box was having apt install problems because of something I did. It's only natural. The Debian project has been rock solid for longer than I've used linux. But it turns out Debian really did just lose the entire bullseye-security repo and no one knows or will comment on if it will ever be returned and restore the ability to use Debian 11. Since it is EOL they consider it a low priority that they just broke probably tens of thousands if not hundreds of thousands of machines.

This is not how it's gone with any other EOL version. And indeed older EOL *-security repo contents are on the archive server. The snapshot servers have the packages so it's just not important enough for anyone responsible for it to fix.

A better bug covering this is at: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147093

Basically for bullseye users with the bullseye-security repo in use there were packages that should have been included in the final point release before they (in bullseye-security) were deleted, instead there are some broken dependency chains because they weren't.

One doesn't need -security updates for bullseye, and this isn't about security or asking for extra extended support. It is about the repos not being in an independent state when bullseye-security went away. And this broke existing installs.

For others with the issue finding this post the mitigation is to use the snapshot servers:

    deb [check-valid-until=no] http://snapshot.debian.org/archive/debian-security/20260903T220410Z/ bullseye-security main
    deb-src [check-valid-until=no] http://snapshot.debian.org/archive/debian-security/20260903T220410Z/ bullseye-security main