5. Issues to be aware of for forky —DRAFT—

Sometimes, changes introduced in a new release have side-effects we cannot reasonably avoid, or they expose bugs somewhere else. This section documents issues we are aware of. Please also read the errata, the relevant packages’ documentation, bug reports, and other information mentioned in Further reading.

5.1. Things to be aware of while upgrading to forky

This section covers items related to the upgrade from trixie to forky.

5.1.3. Things to do before rebooting

When apt full-upgrade has finished, the “formal” upgrade is complete. For the upgrade to forky, there are no special actions needed before performing a reboot.

5.2. Items not limited to the upgrade process

5.2.1. Limitations in security support

There are some packages where Debian cannot promise to provide minimal backports for security issues. These are covered in the following subsections.

Note

The package debian-security-support helps to track the security support status of installed packages.

5.2.1.1. Security status of web browsers and their rendering engines

Debian 14 includes several browser engines which are affected by a steady stream of security vulnerabilities. The high rate of vulnerabilities and partial lack of upstream support in the form of long term branches make it very difficult to support these browsers and engines with backported security fixes. Additionally, library interdependencies make it extremely difficult to update to newer upstream releases. Applications using the webkit2gtk source package (e.g. epiphany) are covered by security support, but applications using qtwebengine (source packages qtwebengine-opensource-src and qt6-webengine) are not.

For general web browser use we recommend Firefox or Chromium. They will be kept up-to-date by rebuilding the current ESR releases for stable. The same strategy will be applied for Thunderbird.

Once a release becomes oldstable, officially supported browsers may not continue to receive updates for the standard period of coverage. For example, Chromium will only receive 6 months of security support in oldstable rather than the typical 12 months.

5.2.1.2. Go- and Rust-based packages

The Debian infrastructure currently has problems with rebuilding packages of types that systematically use static linking. With the growth of the Go and Rust ecosystems it means that these packages will be covered by limited security support until the infrastructure is improved to deal with them maintainably.

In most cases if updates are warranted for Go or Rust development libraries, they will only be released via regular point releases.

5.3. Obsolescence and deprecation

5.3.1. Noteworthy obsolete packages

The following is a list of known and noteworthy obsolete packages (see Obsolete packages for a description).

The list of obsolete packages includes:

5.3.2. Deprecated components for forky

With the next release of Debian 15 (codenamed duke) some features will be deprecated. Users will need to migrate to other alternatives to prevent trouble when updating to Debian 15.

This includes the following features:

5.4. Known severe bugs

Although Debian releases when it’s ready, that unfortunately doesn’t mean there are no known bugs. As part of the release process all the bugs of severity serious or higher are actively tracked by the Release Team, so an overview of those bugs that were tagged to be ignored in the last part of releasing forky can be found in the Debian Bug Tracking System. The following bugs were affecting forky at the time of the release and worth mentioning in this document:

Bug number

Package (source or binary)

Description

1032240

akonadi-backend-mysql

akonadi server not robust against mysql upgrades