Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of July 13, 2026report.ci.commoninternet.net2026-07-15 00:21 UTC

The 2026-07-13 run was still in flight at report time — fourteen recipes had their upgrade PR but the weekly summary had not been written yet (a host disk-full and an expired Gitea bridge token interrupted the run mid-wave), so this page reads the live PR and CI state directly. The headline is keycloak 26.7.0, a security patch carrying four CVE fixes on the identity provider — !testme GREEN, merge it first; custom-html's open nginx 1.31.1→1.31.2 PR (three memory-safety CVEs) is also GREEN and overdue to merge. Three recipes are RED only on stale tests — discourse, lasuite-docs and lasuite-meet each hit an upstream decision to reject Bearer/access tokens on the API, which broke cc-ci's OIDC test assertions; the upgrades themselves converge. lasuite-drive is genuinely RED (collabora/onlyoffice, needs a real diagnosis) and plausible's v2→v3 jump is still being iterated with no current verdict. The rest of the fleet is green routine bumps.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
keycloak26.6.4 → 26.7.0GREEN4build 1120 ✓#5Identity provider — 4 security fixes (admin-role TOCTOU escalation, OIDC redirect param pollution, CIBA brute-force bypass, FGAP role unassign) + Quarkus bump. mariadb 12.3 unchanged. No config changes. GREEN build 1120.
custom-htmlnginx 1.31.1 → 1.31.2 + git v2.54.0GREEN3build 969 ✓#5nginx 1.31.1→1.31.2 security patch (3 memory-safety CVEs) + alpine/git v2.54.0. Static-file serving unaffected. Leftover from the 07-03 run, still GREEN at build 969 — overdue to merge.
lasuite-drivecollabora 25.04 → 26.04 · onlyoffice 9.3 → 9.4FAILEDnoneRED 984 · collabora/onlyoffice#6collabora 25.04.9.4.1→26.04.2.1.1 + onlyoffice 9.3.1.2→9.4.1.2 (both abra-unparseable, hand-edited). RED at build 984 — the first RED was a host disk-full, but the latest run is also red and needs a real diagnosis before merge.
plausiblev2.0.0 → v3.2.1 (+ClickHouse 24.12)FAILEDnoneRED 968 · in-flight#5v2.0.0→v3.2.1 + ClickHouse 23.4→24.12 + image registry migration (Docker Hub→ghcr.io). PR #5 was retitled mid-run to a restore-sleep revert and carries no current !testme verdict; last known verdict RED at build 968. Still being iterated at report time.
discourse3.5.3 → 2026.1.5 (+redis 8.8)STALEnoneRED 1117 · stale tests#6app 3.5.3→2026.1.5 (calver ESR; 239 changes + 29 security) + redis 7.4→8.8 (CVE fixes). RED on TWO stale cc-ci tests (hardcoded 3.5.3 version assertion + stale bitnami base the chaos redeploy can't migrate from). Upgrade chaos-verified correct. 4 open PRs to reconcile (#6, #8, #5, #1).
lasuite-docsimpress v5.3.0 → v5.4.1STALEnoneRED 1121 · stale OIDC test#7impress v5.3.0→v5.4.1 (carries prior nginx 1.31.2 + minio 2025-09-07). RED on one stale test — v5.4.0 deliberately removed DRF Bearer-token auth (cookie sessions only); the OIDC test asserts the old Bearer flow. Lifecycle tiers all pass. minio CVE patch is GitHub-only (no image).
lasuite-meetmeet v1.21.0 → v1.23.0 (+livekit v1.13.3)STALEnoneRED 1122 · stale API-auth test#8meet v1.21.0→v1.23.0 + livekit v1.13.1→v1.13.3. RED on one stale functional test — v1.22.0 rejects user access tokens on the API (security hardening); the test uses a Bearer token. All lifecycle tiers pass. No operator action for the standalone recipe.
matrix-synapsesynapse v1.155.0 → v1.156.0 (+MAS 1.20)GREENnonebuild 1125 ✓#5synapse v1.155.0→v1.156.0 + MAS 1.19→1.20 (extends PR #5's bridge work: signalbridge v0.2606.0, telegram Go-bridgev2 config, bridge DBs 13→14). No breaking changes. Operators with existing bridge data must dump/restore the plain-postgres bridge DBs (13→14).
mattermost-lts10.11.20 → 11.7.6 (ESR)GREENnonebuild 1124 ✓#210.11.20→11.7.6 ESR (low–medium security fixes). 10.11 ESR security support ends 15 Aug 2026 — migrate. postgres held at 15 (major bump is operator-guided). v11 free-offering changes (user limits, GitLab SSO removed from Team ed.). Reconcile with backup-restore fix PR #1 (folded into #2).
gitea1.26.2 → 1.26.4-rootlessGREENnonebuild 1118 ✓#51.26.2→1.26.4-rootless (patch: security fix — don't auto-reactivate disabled users on OAuth2 callback #38009; skips 1.26.3 regression). postgres 15 held (major bump deferred — plain postgres needs dump/restore). 1.27.0 (released today, breaking CSP/reusable-workflow changes) deliberately deferred. Reconcile with app.ini-writable fix PR #4.
mailu2024.06.52 → 2024.06.54GREENnonebuild 1123 ✓#5all 6 mailu/* services 2024.06.52→2024.06.54 (patch bug-fixes: vacation sieve injection escape, admin-UI form-flow fixes). No schema/config changes. Reconcile with backup-labels PR #3 (GREEN 483).
n8n2.28.2 → 2.31.0GREENnonebuild 1129 ✓#52.28.2→2.31.0 (spans 2.29–2.31: unified N8N_WEBHOOK_URL, MCP workflow tools, Entra Service Principal, Kafka mTLS, etc.). No breaking changes; DB migrations auto-run. (Plan targeted 2.30.4; the still-running upgrader advanced the live PR to 2.31.0.)
ghost6.50.0 → 6.52.1-alpineGREENnonebuild 1116 ✓#76.50.0→6.52.1-alpine (Social Web handle prefs, Stripe tax-ID collection, Source v1.7.1/Casper v5.12.1; 6.52.1 automations link fix). mysql held at 8.4 (Ghost doesn't support 9.x).
immichv3.0.1 → v3.0.2GREENnonebuild 1119 ✓#4v3.0.1→v3.0.2 (patch: bugfixes + OAuth linking fix; valkey:9 digest refresh to match immich's pin). postgres 14-vectorchord unchanged. abra FATAs on tag+digest pins → hand-edited.
hedgedocpg 17 → 18-alpineGREENnonebuild 977 ✓#3db pgautoupgrade 17→18-alpine + PGDATA=/var/lib/postgresql/data pin (18-alpine moved PGDATA default; without the pin it fresh-inits and loses data). app 1.11.0 unchanged. cc-ci tests use sqlite so the postgres override isn't exercised by !testme (verified in step-2b).
custom-html-tinygit v2.52.0 → v2.54.0GREENnonebuild 971 ✓#9alpine/git v2.52.0→v2.54.0 (optional git-pull cronjob overlay; bundled git 2.53/2.54 features). app static-web-server 2.43.0 unchanged.
bluesky-pds0.4.219 → 0.4.5009GREENnonebuild 970 ✓#3pds 0.4.219→0.4.5009 (spans the Node 20→24 + index.js→index.ts restructure through @atproto/pds 0.5.9; entrypoint v1→v2). No env/secret/migration changes. Re-verified GREEN (head unchanged since 06-26). Reconcile with routing-fix PR #4.
cryptpadUPTODATEnoneUp-to-date. No open PR this week.
droneUPTODATEnoneUp-to-date. No open PR.
libredeskUPTODATEnoneUp-to-date. No open PR.
uptime-kumaUPTODATEnoneUp-to-date (a prior week's upgrade PR merged). No open PR.
mumbleUPTODATEnone#1Up-to-date. Only a lingering cfold-sweep probe PR #1 (build 732) — not an upgrade, can be closed.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

keycloak 26.7.0 — four security fixes on the identity provider (high) · keycloak
keycloak 26.6.4 → 26.7.0 is a minor security release carrying four fixes — CVE-2026-9796 (admin role-rename TOCTOU lets a manage-clients user escalate realm-wide), CVE-2026-9689 (HTTP Parameter Pollution in the OIDC redirect URI allows response-parameter duplication), CVE-2026-9798 (the CIBA authentication flow bypasses brute-force account lockout) and CVE-2026-11986 (FGAP v1 lets a user unassign any role) — plus a Quarkus bump. As the identity provider fronting other services, keycloak is the highest-priority merge of the week. All new features are opt-in; the three removed niche features (Twitter IDP, token-exchange-external-internal:v2, persistent-sessions batching) are not in the recipe's default config. No config changes; !testme GREEN at build 1120.
nginx 1.31.1 → 1.31.2 — memory-safety CVE batch (high) · custom-html
The nginx 1.31.1 → 1.31.2 patch closes three memory-safety CVEs: CVE-2026-42530 (a QUIC use-after-free), CVE-2026-42055 (an HTTP/2 heap buffer overflow) and CVE-2026-48142 (a charset_map overread). It ships GREEN this week in custom-html (PR #5, build 969), bundled with an alpine/git v2.52.0 → v2.54.0 sidecar bump. custom-html uses nginx for static-file serving, where the affected modules are not exercised, but the memory-safety fixes are worth taking regardless. This PR is a leftover from the 07-03 run — still open, still GREEN — and is overdue to merge.

What changed

26.6.4 → 26.7.0. A minor security release: four CVE fixes (admin-role TOCTOU escalation, OIDC redirect param pollution, CIBA brute-force bypass, FGAP role unassign) plus a Quarkus bump and a routine MariaDB held at 12.3. All new features are opt-in; the three removed niche features are not in the default config, so no config changes. An older upgrade PR is no longer open — #5 is the one to merge.
nginx 1.31.1 → 1.31.2 brings the 1.31.2 memory-safety CVE batch (QUIC UAF, HTTP/2 heap overflow, charset_map overread); alpine/git bumped v2.52.0 → v2.54.0. linuxserver/openssh-server left at its intentional latest pin. This is the leftover 07-03 PR, re-confirmed GREEN at build 969 — merge it to land the nginx CVE fixes.
collabora 25.04.9.4.1 → 26.04.2.1.1 (CODE 25.04 → 26.04 year-line) and onlyoffice 9.3.1.2 → 9.4.1.2 (9.4 backend consolidation, internal-only). Both tags are abra-unparseable so were hand-edited. RED at build 984: the first failure was the host disk running 100% full, but the latest run is also red and needs a real diagnosis before merge.
v2.0.0 → v3.2.1 + ClickHouse 23.4 → 24.12 + an image-registry migration (Docker Hub plausible/analytics → ghcr.io plausible/community-edition). The 07-13 run added a CLICKHOUSE_USER_CONF_VERSION v2→v3 bump to fix a Docker-config immutability conflict on the chaos redeploy, then a restore-sleep revert for the pgautoupgrade window. PR #5 was retitled mid-run and has no current !testme verdict; last known verdict RED at build 968. Still being iterated.
app 3.5.3 → 2026.1.5 (the calver ESR line; 239 changes incl. 18 security, plus 11 more in 2026.1.5) + redis 7.4 → 8.8-alpine (8.0.2–8.0.6 CVE fixes; 7.x RDB loads cleanly). db discourse/postgres:pg18 left as-is. RED at build 1117 on two stale cc-ci tests (a hardcoded 3.5.3 image assertion, and a stale bitnami base the chaos redeploy can't migrate from). The upgrade itself is chaos-verified correct. Four open PRs to reconcile.
impress v5.3.0 → v5.4.1 (carried on PR #7 alongside the prior nginx 1.31.2 + minio 2025-09-07 bumps). v5.4.0 deliberately removed DRF Bearer-token auth — the API now uses cookie sessions only — which is the new correct behavior; the stale OIDC test asserts the old Bearer flow. All lifecycle tiers pass; RED at build 1121 is the single stale test. minio has a GitHub-only CVE patch that was never published as a container image (repo archived).
meet v1.21.0 → v1.23.0 (recording egress fallback, PiP cap, summary API v2 migration, analytics) + livekit v1.13.1 → v1.13.3. v1.22.0 rejects user access tokens on the API — a security hardening that breaks the stale functional test (it uses a Bearer token). All lifecycle tiers pass; RED at build 1122 is that one stale test. No operator action for the standalone recipe (the SUMMARY_SERVICE_VERSION:2 note does not apply).
synapse v1.155.0 → v1.156.0 (MSC4354 Sticky Events, MSC2409 ephemeral events, MSC4140 delayed-event auth) + MAS 1.19 → 1.20 (client IP tracking, device-auth-grant). Extends PR #5's bridge work (signalbridge v0.2606.0, telegram Go-bridgev2 config rewrite, bridge DBs 13 → 14-alpine). No breaking changes. Operators with existing bridge data must dump/restore each plain-postgres bridge DB before deploying. GREEN build 1125.
2024.06.52 → 2024.06.54 across all six mailu/* services. 2024.06.53 fixes vacation/reply sieve injection via the account display name; 2024.06.54 fixes two admin-UI form-flow bugs. Patch bug-fixes, no schema/config changes. GREEN build 1123. Reconcile with the backupbot-labels PR #3 (GREEN build 483).
10.11.20 → 11.7.6 ESR — a major ESR jump carrying low–medium security fixes. 10.11 ESR security support ends 15 Aug 2026, so this is the migration to make. postgres held at 15-alpine (a major pg bump is a separate operator-guided dump/restore). Be aware of v11 free-offering changes (Entry 50-user / Team 250-user limits, GitLab SSO removed from Team edition). GREEN build 1124. The backup-restore fix PR #1 is now folded into #2.
2.28.2 → 2.31.0, spanning 2.29 (configurable blocked hostnames, Entra Service Principal, MCP workflow history tools, Slack schedule message) and 2.30 (unified N8N_WEBHOOK_URL, Kafka mTLS, Excel/Teams Service Principal auth), plus 2.30.x–2.31.x bugfixes. No breaking changes; DB migrations auto-run on startup. The plan targeted 2.30.4 but the still-running upgrader advanced the live PR to 2.31.0 (GREEN build 1129).
6.50.0 → 6.52.1-alpine: Social Web handle preferences, Stripe tax-ID collection when automatic tax enabled, Source v1.7.1 + Casper v5.12.1, and a 6.52.1 automations email-editor link-selection fix. 6.52.0 removed the discontinued Tenor GIF provider (admin UI only). mysql held at 8.4 LTS — Ghost only certifies mysql 8.x. GREEN build 1116.
1.26.2 → 1.26.4-rootless: a patch carrying a security fix (don't auto-reactivate disabled users on the OAuth2 callback, #38009) and a git-log context error fix; 1.26.3 is skipped (a “context deadline exceeded” regression). postgres 15 held — a major bump needs an operator dump/restore. 1.27.0 (released the same day, with breaking CSP / reusable-workflow changes) is deliberately deferred to a dedicated minor-bump run. PR #5 was re-baselined onto current master so the stale FORGE=gitea re-addition dropped out. Reconcile with the app.ini-writable fix PR #4. GREEN build 1118.
v3.0.1 → v3.0.2: a patch with bugfixes, an OAuth linking fix and HLS/transcoding fixes; the valkey:9 digest pin is refreshed to match immich v3.0.2's own compose pin. postgres 14-vectorchord unchanged (no pg-major migration). abra FATAs on the tag+digest pins, so all image edits are hand-edits. GREEN build 1119.
alpine/git v2.52.0 → v2.54.0 on the optional git-pull cronjob overlay (bundles git 2.53/2.54: a new experimental git history command, geometric repack default). The app image (joseluisq/static-web-server 2.43.0) is unchanged. No clone/fetch/pull behavior change. GREEN build 971.
pds 0.4.219 → 0.4.5009, spanning the Node 20 → 24 + index.js → index.ts restructure (entrypoint v1 → v2) through @atproto/pds 0.5.9 (resilient background queue, undici v8, pino v10). No env/secret/migration changes across the whole journey. 0.4.5009 is still the newest upstream tag; the head is unchanged since 06-26 and re-verified GREEN at build 970. Reconcile with the routing-rename fix PR #4.
db pgautoupgrade 17 → 18-alpine with a PGDATA=/var/lib/postgresql/data pin — 18-alpine moved its default PGDATA to /var/lib/postgresql/18/docker, so without the pin a plain tag bump fresh-inits an ephemeral cluster and the 17 data is lost. The pin restores the volume mount. app hedgedoc 1.11.0 unchanged. cc-ci's !testme exercises the sqlite backend, so the postgres override is verified in the step-2b direct deploy (16→17→18 clean). GREEN build 977.