But, returning to my main bug described: I start a fresh vm with Debian 13.6 cloud image, trusting it is built from release branch, not leaked after updates.
I disable the stable-updates, because I want less paper work (some audited companies must list every possible element of updates, disabling the stable-updates, and getting them every 2 months is more than perfect). I try to install next unbound, but can’t, it has a dependency on a python package, that has a dependency of another python package that is in unstable now, but I can’t because I limited to stable+security. Do you see the bug I try to express? And my proposal it can help everybody: Build the cloud release skipping stable-updates, only stable+security, and keep enabled the stable-updates in apt sources. So, the build gets 100% release, potentially with some security updated packages. You understand the steps that can help all possible situations, and all system admins, mainly who work in environments with more audit on each change? I repeat, I do not suggest to permanently disable stable-updates. This must stay, as they were always with Debian. But to the release with that release lists, not a technically optional update. Regards, Madalin > On 26 Aug 2026, at 18:39, Noah Meyerhans <[email protected]> wrote: > > The repository information in the Debian Reference is not false. The > updates repository (and the security repository, for that matter!) is > optional, from a purely technical perspective. That is, nothing in the > main repository depends on content from them. Any package in the main > repository can be installed with all dependencies satisfied within that > repository.

