Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

CVE check · 11 August 2026report.ci.commoninternet.net2026-08-11 04:56 UTC

Two recipes carry pending CVE fixes. plausible's clickhouse bump closes four — and was invisible to every previous survey, because abra cannot parse that tag and so contributed nothing for it. mailu is the other: two Roundcube webmail flaws on an internet-facing mail host. Everything else with an upgrade available fixes nothing security-relevant. All 21 recipes resolved this run, including immich, which had been silently dropping out of surveys entirely.

Advisory sweep — every recipe, worst first

RecipeChangeTESTSCVEsCIPRSTATUSNotes
plausibleclickhouse 23.4.2.11 → 23.10.4.25-alpinePENDING4Found only because the resolver reads registries directly — abra cannot parse this tag, so this upgrade was invisible to every previous survey. Three high (CVE-2023-47118, CVE-2023-48704 line, CVE-2024-6873), one medium, one low. Note CVE-2023-48704 is NOT counted: its fix on the 23.10 line is 23.10.5.20, above this target.
mailu2024.06.55 → 2024.06.57 · redis 8.8.0 → 8.10.0PENDING2Roundcube 1.6.17 CVEs CVE-2026-54432/54433, named in Mailu release 2024.06.56 — inside this window. Internet-facing webmail. The redis bump fixes nothing new: all 12 advisories it crosses were already fixed at or before 8.6.3.
giteamariadb 10.11.2 → 10.11.18 (app current at 1.27.1)PENDINGnoneApp is current; its two CVSS-9.8 RCEs were fixed by 1.27.1, already pinned. The mariadb sidecar is 16 patch releases behind — no CVEs attributable to that window, but worth taking.
immichpostgres pgvectors 0.2.0 → 0.3.0 (pg14)PENDINGnonePreviously unscannable — abra aborts on this recipe's tag+digest pins. Now fully resolved: app images are current at v3.1.0. Stay within pg14; the newest tag jumps to pg17 and would break it.
mattermost-lts10.11.22 → 10.12.4 · postgres 15 → 18PENDINGnoneScanned within the LTS 10.x line; 11.x exists but is off-track. Weak evidence base — see Addendum.
bluesky-pds0.4.219 → 0.4.5026PENDINGnone13 advisories seen, none in this window.
ghost6.56.0 → 6.57.0 (alpine)PENDINGnone34 advisories seen, all outside this window. mysql 8.4 offers only 9.x/26.7 — outside Ghost 6's supported matrix, so no window was invented for it.
mumblev1.6.870-0 → v1.6.870-4PENDINGnoneabra reported 'no new versions' for this image; the resolver found four patch releases. No CVEs.
lasuite-drivecollabora 25.04.10.3.1 (newest in line)PENDINGnoneabra cannot parse collabora's tag. Resolver confirms current within its line; 26.04 exists as a major jump, not scanned.
hedgedocpgautoupgrade 16 → 18 (no app bump)PENDINGnoneSidecar-only; pgautoupgrade publishes no advisories. HedgeDoc itself is current.
matrix-synapsepostgres 13 → 18 (bridge DBs, no app bump)PENDINGnoneSynapse current at v1.158.0. Postgres publishes no GitHub advisories. Five-major DB jump.
n8n2.34.2 → 2.34.4PENDINGnone84 advisories seen, all outside this window.
cryptpadUPTODATEnoneNo upgrade available — nothing an upgrade could fix.
custom-htmlUPTODATEnoneNo upgrade available — nothing an upgrade could fix.
custom-html-tinyUPTODATEnoneNo upgrade available — nothing an upgrade could fix.
discourseUPTODATEnoneNow at 2026.7.1 + redis 8.10-alpine: the 140-CVE ESR upgrade has landed, including the critical redis CVE-2025-49844.
droneUPTODATEnoneNo upgrade available — nothing an upgrade could fix.
keycloakUPTODATEnoneCurrent at 26.7.1. That upgrade fixed 12 CVEs, not the 7 reported on 2026-08-07 — five more are named only in the 26.7.1 release notes.
lasuite-docsUPTODATEnoneNo upgrade available — nothing an upgrade could fix.
lasuite-meetUPTODATEnoneNo upgrade available — nothing an upgrade could fix.
wordpressUPTODATEnoneNo upgrade available — nothing an upgrade could fix.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

plausible — ClickHouse CVE-2023-47118 (high) and CVE-2024-6873 (high)
The clickhouse sidecar is pinned at 23.4.2.11-alpine and can move to 23.10.4.25-alpine, closing four advisories including two high-severity ones. This upgrade had never been surveyed: abra cannot parse the tag and silently contributed nothing for the image, so it appeared as 'no upgrades available' on every previous run. Not internet-facing in the way mailu is, but it is the largest single block of unfixed CVEs the sweep found.
mailu — Roundcube webmail CVE-2026-54432 / CVE-2026-54433 · internet-facing
Mailu 2024.06.56 rolls up Roundcube 1.6.17, fixing both. The recipe pins 2024.06.55, so both are open; the available 2024.06.57 bump closes them. Webmail is exposed on a mail host. Both were assessed high on 2026-08-07; the scan's source is Mailu's release notes, which name the CVEs but carry no severity field. The same PR's redis bump is housekeeping — every redis advisory it crosses was already fixed by 8.6.3.