Two recipes carry pending CVE fixes. plausible's clickhouse bump closes four — and was invisible to every previous survey, because abra cannot parse that tag and so contributed nothing for it. mailu is the other: two Roundcube webmail flaws on an internet-facing mail host. Everything else with an upgrade available fixes nothing security-relevant. All 21 recipes resolved this run, including immich, which had been silently dropping out of surveys entirely.
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|
| plausible | clickhouse 23.4.2.11 → 23.10.4.25-alpine | PENDING | 4 | | | | Found only because the resolver reads registries directly — abra cannot parse this tag, so this upgrade was invisible to every previous survey. Three high (CVE-2023-47118, CVE-2023-48704 line, CVE-2024-6873), one medium, one low. Note CVE-2023-48704 is NOT counted: its fix on the 23.10 line is 23.10.5.20, above this target. |
| mailu | 2024.06.55 → 2024.06.57 · redis 8.8.0 → 8.10.0 | PENDING | 2 | | | | Roundcube 1.6.17 CVEs CVE-2026-54432/54433, named in Mailu release 2024.06.56 — inside this window. Internet-facing webmail. The redis bump fixes nothing new: all 12 advisories it crosses were already fixed at or before 8.6.3. |
| gitea | mariadb 10.11.2 → 10.11.18 (app current at 1.27.1) | PENDING | none | | | | App is current; its two CVSS-9.8 RCEs were fixed by 1.27.1, already pinned. The mariadb sidecar is 16 patch releases behind — no CVEs attributable to that window, but worth taking. |
| immich | postgres pgvectors 0.2.0 → 0.3.0 (pg14) | PENDING | none | | | | Previously unscannable — abra aborts on this recipe's tag+digest pins. Now fully resolved: app images are current at v3.1.0. Stay within pg14; the newest tag jumps to pg17 and would break it. |
| mattermost-lts | 10.11.22 → 10.12.4 · postgres 15 → 18 | PENDING | none | | | | Scanned within the LTS 10.x line; 11.x exists but is off-track. Weak evidence base — see Addendum. |
| bluesky-pds | 0.4.219 → 0.4.5026 | PENDING | none | | | | 13 advisories seen, none in this window. |
| ghost | 6.56.0 → 6.57.0 (alpine) | PENDING | none | | | | 34 advisories seen, all outside this window. mysql 8.4 offers only 9.x/26.7 — outside Ghost 6's supported matrix, so no window was invented for it. |
| mumble | v1.6.870-0 → v1.6.870-4 | PENDING | none | | | | abra reported 'no new versions' for this image; the resolver found four patch releases. No CVEs. |
| lasuite-drive | collabora 25.04.10.3.1 (newest in line) | PENDING | none | | | | abra cannot parse collabora's tag. Resolver confirms current within its line; 26.04 exists as a major jump, not scanned. |
| hedgedoc | pgautoupgrade 16 → 18 (no app bump) | PENDING | none | | | | Sidecar-only; pgautoupgrade publishes no advisories. HedgeDoc itself is current. |
| matrix-synapse | postgres 13 → 18 (bridge DBs, no app bump) | PENDING | none | | | | Synapse current at v1.158.0. Postgres publishes no GitHub advisories. Five-major DB jump. |
| n8n | 2.34.2 → 2.34.4 | PENDING | none | | | | 84 advisories seen, all outside this window. |
| cryptpad | — | UPTODATE | none | | | | No upgrade available — nothing an upgrade could fix. |
| custom-html | — | UPTODATE | none | | | | No upgrade available — nothing an upgrade could fix. |
| custom-html-tiny | — | UPTODATE | none | | | | No upgrade available — nothing an upgrade could fix. |
| discourse | — | UPTODATE | none | | | | Now at 2026.7.1 + redis 8.10-alpine: the 140-CVE ESR upgrade has landed, including the critical redis CVE-2025-49844. |
| drone | — | UPTODATE | none | | | | No upgrade available — nothing an upgrade could fix. |
| keycloak | — | UPTODATE | none | | | | Current at 26.7.1. That upgrade fixed 12 CVEs, not the 7 reported on 2026-08-07 — five more are named only in the 26.7.1 release notes. |
| lasuite-docs | — | UPTODATE | none | | | | No upgrade available — nothing an upgrade could fix. |
| lasuite-meet | — | UPTODATE | none | | | | No upgrade available — nothing an upgrade could fix. |
| wordpress | — | UPTODATE | none | | | | No upgrade available — nothing an upgrade could fix. |