diff --git a/howto/upgrades/bullseye.md b/howto/upgrades/bullseye.md
index 5f5caf4405df78008ab2a1b8e1d942a6ee10b366..decb6c4192a12a17236cd9b6ded568e51e2ece9a 100644
--- a/howto/upgrades/bullseye.md
+++ b/howto/upgrades/bullseye.md
@@ -301,7 +301,10 @@ perspective:
  * persistent systemd journal, which might have some privacy issues
    (`rm -rf /var/log/journal` to disable, see [journald.conf(5)](https://manpages.debian.org/bullseye/systemd/journald.conf.5.en.html))
  * last release to support non-merged /usr
- * security archive changed to `deb https://deb.debian.org/debian-security bullseye-security main contrib` (covered by script above)
+ * security archive changed to `deb
+   https://deb.debian.org/debian-security bullseye-security main
+   contrib` (covered by script above, also requires a change in
+   unattended-upgrades)
  * [password hashes have changed](https://www.debian.org/releases/bullseye/amd64/release-notes/ch-information.en.html#pam-default-password) to [yescrypt](https://www.openwall.com/yescrypt/) (recognizable
    from its `$y$` prefix), a major change from the previous default,
    SHA-512 (recognizable from its `$6$` prefix), see also