{"id":12551,"date":"2026-08-03T10:13:23","date_gmt":"2026-08-03T08:13:23","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=12551"},"modified":"2026-08-03T10:13:27","modified_gmt":"2026-08-03T08:13:27","slug":"debian-sources-list-and-repository-components-explained","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/debian-sources-list-and-repository-components-explained\/","title":{"rendered":"Debian sources.list and Repository Components Explained"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Debian repository definitions, including <code>sources.list<\/code>, tell APT where to find packages and which parts of the Debian archive are available to your system. A default installation may use only selected components, so software can appear to be missing even when it exists in another repository component or release channel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The main choices are <strong>main<\/strong>, <strong>contrib<\/strong>, and <strong>non-free<\/strong>. Separate sources provide security fixes, normal Stable updates, and selected newer packages through Backports. Reviewing these definitions helps you understand what your system can install and reduces the risk of combining incompatible Debian releases.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/debian-sources-list-and-repository-components-explained\/#How_a_Debian_repository_definition_is_organised\" >How a Debian repository definition is organised<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/debian-sources-list-and-repository-components-explained\/#Traditional_sourceslist_format\" >Traditional sources.list format<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/debian-sources-list-and-repository-components-explained\/#Modern_deb822_source_format\" >Modern deb822 source format<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/debian-sources-list-and-repository-components-explained\/#What_main_contrib_and_non-free_mean\" >What main, contrib, and non-free mean<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/debian-sources-list-and-repository-components-explained\/#Security_and_updates_sources\" >Security and updates sources<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/debian-sources-list-and-repository-components-explained\/#What_Backports_are_used_for\" >What Backports are used for<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/debian-sources-list-and-repository-components-explained\/#How_repository_signing_protects_package_metadata\" >How repository signing protects package metadata<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/debian-sources-list-and-repository-components-explained\/#Why_mixing_Stable_Testing_and_Unstable_is_risky\" >Why mixing Stable, Testing, and Unstable is risky<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/debian-sources-list-and-repository-components-explained\/#Safe_checks_before_changing_repository_definitions\" >Safe checks before changing repository definitions<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_a_Debian_repository_definition_is_organised\"><\/span>How a Debian repository definition is organised<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-4274645345\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">A repository entry normally identifies five things: the package source type, the repository location, the Debian release or suite, the repository component, and the key used to verify its signatures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The release is often called a suite. A Stable system may use a release codename or the name <code>stable<\/code>. A source can also point to a security suite, an updates suite, or Backports. The component tells APT which section of that release to search.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These definitions do not install software by themselves. They make package indexes available to APT. After the indexes are refreshed, APT can select packages from the enabled sources while checking their version, dependencies, and signatures.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Traditional_sourceslist_format\"><\/span>Traditional sources.list format<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The traditional format stores one repository definition on each line. A line contains the type, URI, suite, and one or more components. A simplified structure looks like this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>deb &lt;repository-URI&gt; &lt;suite&gt; &lt;component&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For example, the same suite may have separate entries for <code>main<\/code>, <code>contrib<\/code>, and <code>non-free<\/code>. A source can list several components on one line when they use the same URI and suite.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Lines beginning with <code>#<\/code> are comments and are not used by APT. Traditional entries are commonly stored in <code>\/etc\/apt\/sources.list<\/code> or in files ending with <code>.list<\/code> inside <code>\/etc\/apt\/sources.list.d\/<\/code>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Modern_deb822_source_format\"><\/span>Modern deb822 source format<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The deb822 format stores one source as a group of named fields. It is easier to read when a source has several options. A simplified structure looks like this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Types: deb\nURIs: &lt;repository-URI&gt;\nSuites: &lt;suite&gt;\nComponents: main contrib\nSigned-By: &lt;key-file&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Field names make the purpose of each value clear. A deb822 source normally uses a <code>.sources<\/code> file in <code>\/etc\/apt\/sources.list.d\/<\/code>. The exact fields can vary when a source needs more settings, but the same basic information is required: where the repository is, which suite to use, and which components to enable.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_main_contrib_and_non-free_mean\"><\/span>What main, contrib, and non-free mean<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Component<\/th><th>What it contains<\/th><th>Why software may be missing<\/th><\/tr><\/thead><tbody><tr><td>main<\/td><td>Debian&#8217;s primary free software archive.<\/td><td>A package may be in another component or may not be available for the selected release.<\/td><\/tr><tr><td>contrib<\/td><td>Free software that depends on software outside the main archive.<\/td><td>It is not available when only main is enabled.<\/td><\/tr><tr><td>non-free<\/td><td>Software that does not meet Debian&#8217;s free software requirements.<\/td><td>It must be enabled separately, and some installations do not enable it by default.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Enabling a component makes its package indexes available. It does not mean that every package in that component will be installed. Package dependencies and the selected Debian release still control which versions APT can use.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Security_and_updates_sources\"><\/span>Security and updates sources<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Stable receives security updates through Debian&#8217;s security workflow. A security source allows APT to receive those fixes separately from the main Stable archive. Stable also has an updates source for important package updates that are released during the Stable lifecycle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Automatic updates can apply many package fixes, but they do not cover every security task. Users still need to keep package lists current, review available updates, and check that the expected security and updates sources are enabled. The exact suite name depends on the Debian release. Use the matching security and updates suites for the Stable release installed on the system.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Backports_are_used_for\"><\/span>What Backports are used for<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Backports provide selected newer software for a Stable system. These packages are adapted for Stable rather than changing the whole system to a newer Debian release. Backports are useful when a Stable package is too old for a specific need and a compatible newer version is available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Backports are not a replacement for the normal Stable or security sources. Keep the regular Stable sources enabled, and treat Backports as an additional source for selected packages. A package from Backports can have different dependencies and update behaviour, so review the package version and source before using it on an important system.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_repository_signing_protects_package_metadata\"><\/span>How repository signing protects package metadata<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Debian repositories publish signed metadata. APT checks this metadata against trusted archive signing keys before accepting package indexes. This helps confirm that the repository information has not been changed after publication.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <code>Signed-By<\/code> setting can restrict a source to a specific key file. This is useful because it connects that repository definition with the key intended for it. Do not disable signature checks to make a source work. A missing, expired, or untrusted key should be treated as a source configuration issue that needs verification.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_mixing_Stable_Testing_and_Unstable_is_risky\"><\/span>Why mixing Stable, Testing, and Unstable is risky<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Stable, Testing, and Unstable are different Debian development stages with different package versions and dependency sets. A system that combines them can receive packages that expect newer libraries, tools, or system components than Stable provides.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mixing releases can therefore lead to dependency conflicts, unexpected upgrades, or a system that is difficult to return to a consistent release. It can also change the update path for packages that were previously managed by Stable. Use one primary Debian release for the system. If a newer package is needed on Stable, check Backports before adding Testing or Unstable.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Safe_checks_before_changing_repository_definitions\"><\/span>Safe checks before changing repository definitions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Identify the Debian release currently installed.<\/li>\n\n\n\n<li>List all files that define APT sources, including both <code>.list<\/code> and <code>.sources<\/code> files.<\/li>\n\n\n\n<li>Check that the main suite, security suite, and updates suite all match the installed Stable release.<\/li>\n\n\n\n<li>Confirm that each enabled component is needed, such as main, contrib, or non-free.<\/li>\n\n\n\n<li>Check the signing configuration and do not bypass signature verification.<\/li>\n\n\n\n<li>Review any Testing, Unstable, or Backports entry before enabling it.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">A package missing from search results does not always mean it has been removed. The package may be in contrib or non-free, may belong to another Debian release, or may not be available for the installed architecture. Repository definitions should be changed one source at a time so that any resulting change is easier to identify.<\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[42],"manual_kb_tag":[],"class_list":["post-12551","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-miscellaneous"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/12551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/12551\/revisions"}],"predecessor-version":[{"id":12580,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/12551\/revisions\/12580"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=12551"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=12551"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=12551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}