Skip to content

Debian bullseye images can no longer be built (bullseye reached end of life); proposal: stop building them #50

Description

@fdcastel

Problem

Bullseye images can no longer be built. The prerequisite apt-get install step fails on debian:bullseye-slim for every Firebird version:

E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/c/curl/curl_7.74.0-1.3%2bdeb11u16_amd64.deb  404  Not Found
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/o/openssl/openssl_1.1.1w-0%2bdeb11u8_amd64.deb  404  Not Found
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/i/icu/libicu67_67.1-7%2bdeb11u1_amd64.deb  404  Not Found
E: Failed to fetch http://deb.debian.org/debian-security/pool/updates/main/libt/libtommath/libtommath1_1.2.0-6%2bdeb11u1_amd64.deb  404  Not Found
...

This is not related to our Dockerfile. A stock debian:bullseye-slim container reproduces it with just apt-get update && apt-get install curl.

Cause

Debian 11 "bullseye" reached the end of its LTS period on 2026-08-31, and Debian is moving it off the main mirrors:

  • The bullseye-security index on deb.debian.org still lists curl 7.74.0-1.3+deb11u16, but the .deb it points to now returns 404.
  • archive.debian.org, where end-of-life releases end up, does not have bullseye-security yet either (also 404).
  • The regular bullseye suite on deb.debian.org still works, but apt prefers the newer versions from the security index, so the install fails anyway.

Impact

  • New bullseye images (*-bullseye tags, e.g. 5.0.4-bullseye, 5-bullseye, bullseye) cannot be built, for any Firebird version.
  • CI builds fail on bullseye. Since the build stops at the first failed image, the distros that come after bullseye are not built or tested either. For example, the CI run of Fix SYSDBA.password not working in Firebird 3 images #49 had to be validated with separate per-distro runs.
  • Images already published on Docker Hub are not affected. They just won't be rebuilt.

Proposal

Stop building bullseye images from now on:

  • Remove bullseye from the build matrix in assets.json for new builds, and record the decision in DECISIONS.md.
  • Keep the existing bullseye tags on Docker Hub as they are (no deletion).
  • Update the README to say bullseye is no longer built, and point users to trixie (the default) or bookworm.

Even if the Debian mirrors are fixed or bullseye is repointed to archive.debian.org, bullseye no longer receives security updates. New bullseye images would ship unpatched OpenSSL, curl and ICU, so continuing to build them doesn't seem worthwhile.

Feedback wanted

This issue will stay open for a while before any change is made. If you depend on the bullseye images, please comment here with your use case and what keeps you from moving to bookworm or trixie.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions