3 comments
This is not how it's gone with any other EOL version. And indeed older EOL *-security repo contents are on the archive server. The snapshot servers have the packages so it's just not important enough for anyone responsible for it to fix.
Basically for bullseye users with the bullseye-security repo in use there were packages that should have been included in the final point release before they (in bullseye-security) were deleted, instead there are some broken dependency chains because they weren't.
One doesn't need -security updates for bullseye, and this isn't about security or asking for extra extended support. It is about the repos not being in an independent state when bullseye-security went away. And this broke existing installs.
For others with the issue finding this post the mitigation is to use the snapshot servers:
deb [check-valid-until=no] http://snapshot.debian.org/archive/debian-security/20260903T220410Z/ bullseye-security main
deb-src [check-valid-until=no] http://snapshot.debian.org/archive/debian-security/20260903T220410Z/ bullseye-security mainRead the full thread on Hacker News →
Related stories
- Hacker News · 1 points · 3 days ago
- Forging 1024-bit RSA signatures in nearly SNFS timeeprint.iacr.orgLobsters · 7 points · 6 days ago
- Ars Technica · 0 points · 9 days ago
- DEV Community · 9 points · 17 days ago
- On Improvements of Low-Deterministic Security (2016)pp.ipd.kit.eduLobsters · 2 points · about 8 years ago
- Hacker News · 1 points · 4 days ago