"Error installing requirements" — expired Debian bullseye-security Release file, confirmed across 4 rebuild attempts

I’m getting a persistent “Error installing requirements” failure on Streamlit Community Cloud. This is not a requirements.txt problem — the failure happens during the apt (system package) step, before pip ever runs, and it’s failed identically on every rebuild/reboot I’ve tried over the last day.

Log showing 4 separate attempts, same error each time (note the “invalid since” duration climbing):

[13:35:25] E: Release file for http://deb.debian.org/debian-security/dists/bullseye-security/InRelease is expired (invalid since 16h 22min 20s).
[13:39:42] E: Release file for http://deb.debian.org/debian-security/dists/bullseye-security/InRelease is expired (invalid since 16h 26min 37s).
[13:50:58] E: Release file for http://deb.debian.org/debian-security/dists/bullseye-security/InRelease is expired (invalid since 16h 37min 53s).
[14:00:19] E: Release file for http://deb.debian.org/debian-security/dists/bullseye-security/InRelease is expired (invalid since 16h 47min 14s).

Each time: installer returned a non-zero exit code / Error during processing dependencies!

What I’ve tried: Rebooting the app multiple times (log above), which just re-triggers the same failing build. As a workaround, I emptied packages.txt so the apt step is skipped entirely — that lets the deploy succeed, but I’d rather not run without tesseract-ocr (needed for OCR on scanned PDFs) long-term.

Versions: Streamlit 1.40.2, Python 3.12

Deployment: Streamlit Community Cloud (not running locally)

packages.txt (before my workaround):

tesseract-ocr

requirements.txt (full contents):

streamlit==1.40.2
pdfplumber==0.11.4
pymupdf==1.24.14
openpyxl==3.1.5
python-docx==1.2.0
anthropic==0.111.0
openai==2.42.0
python-dotenv==1.2.2
pillow==11.3.0
pandas==2.3.3
pytesseract==0.3.13
rapidfuzz==3.10.1

This looks like a stale/broken Debian security mirror baked into the build image on Streamlit’s side (bullseye-security’s Release file is never refreshing, only getting more expired with each attempt), not something fixable from my repo. Has anyone else hit this, or does the Streamlit team know about it?

Hey, thanks for sharing such a detailed report and welcome to the Streamlit community! :balloon: You’re absolutely right—this “Release file is expired” error for bullseye-security during the apt step is a known issue with the underlying Debian security mirror used by Streamlit Community Cloud. It’s not caused by your code, requirements.txt, or packages.txt, and rebooting or redeploying won’t resolve it on your end. This happens when the base image’s apt sources point to a security repo whose Release file has expired, and only the Streamlit platform team can update or refresh the build image to fix it.

The best workaround is what you’ve already done: temporarily remove or empty packages.txt to skip the apt step, allowing your app to deploy (but without system packages like tesseract-ocr). Once the Streamlit team refreshes the build image or the Debian mirror updates, you can restore packages.txt and redeploy. This issue has occurred before and is typically resolved by the platform maintainers without user intervention. For more details and community discussion, see this forum thread and the official docs on apt dependencies.

Sources:

Thanks so much for flagging @Derk!

The team is aware and fix is in the works. :folded_hands:

Hey @Derk , thanks for reporting the issue to us! We have rolled out a new version to prod which should fix the issue! Please let us know if something is still not working and sorry for the inconvenience :slight_smile: