Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of July 17, 2026report.ci.commoninternet.net2026-07-17 02:41 UTC

Nothing was merged this week, so the priority picture is unchanged: merge the two high-severity CVE PRs first — keycloak 26.7.0 (four CVEs on the identity provider) and custom-html's nginx 1.31.2 (three memory-safety CVEs), both !testme GREEN and open since the 07-03/07-13 runs. The /upgrade-all run itself was quiet — 19 of 20 recipes already up-to-date, the only new upgrade immich v3.0.2 → v3.0.3 (a patch, GREEN at build 1130). Then unblock discourse, lasuite-docs and lasuite-meet — RED only because an upstream API-auth hardening broke cc-ci's OIDC test fixtures, not the upgrades — diagnose lasuite-drive's genuine collabora/onlyoffice RED, and clear the routine GREEN bumps.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
keycloak26.6.4 → 26.7.0GREEN4build 1120 ✓#5Identity provider — 4 CVE fixes (admin-role TOCTOU, OIDC redirect-param pollution, CIBA brute-force bypass, FGAP role unassign) + Quarkus bump. GREEN since 07-13; overdue to merge.
custom-htmlnginx 1.31.1 → 1.31.2 + git v2.54.0GREEN3build 969 ✓#5nginx 1.31.1→1.31.2 (3 memory-safety CVEs: QUIC UAF, HTTP/2 heap overflow, charset_map overread) + alpine/git v2.54.0. Open & GREEN since 07-03 — overdue to merge.
lasuite-drivecollabora 25.04 → 26.04 · onlyoffice 9.3 → 9.4FAILEDnoneRED 984 · collabora/onlyoffice#6collabora 25.04→26.04 + onlyoffice 9.3→9.4 (both abra-unparseable, hand-edited). RED at 984 — first failure was disk-full, latest still red; needs real diagnosis. Close stray sweep #3.
discourse3.5.3 → 2026.1.5 (+redis 8.8)STALEnoneRED 1117 · stale tests#6app 3.5.3→2026.1.5 (239 chg incl. 18 security) + redis 7.4→8.8. RED on two stale cc-ci tests (hardcoded 3.5.3 assertion + bitnami base), not the upgrade. 4 open PRs to reconcile (#6,#8,#5,#1).
lasuite-docsimpress v5.3.0 → v5.4.1STALEnoneRED 1121 · stale OIDC test#7impress v5.3.0→v5.4.1. RED at 1121 on one stale OIDC test (v5.4.0 removed Bearer auth for cookie sessions — new correct behavior). Lifecycle tiers pass. minio CVE unfixable (image archived).
lasuite-meetmeet v1.21.0 → v1.23.0 (+livekit v1.13.3)STALEnoneRED 1122 · stale API-auth test#8meet v1.21.0→v1.23.0 + livekit v1.13.1→v1.13.3. RED at 1122 on one stale API-auth test (v1.22.0 rejects user access tokens — security hardening). Lifecycle tiers pass.
plausiblev2.0.0 → v3.2.1 (+ClickHouse 24.12)STALEnoneno verdict · re-run !testme#5PR #5 rebased from the v2→v3 + ClickHouse 24.12 jump to a small 'restore sleep 10' revert. Current head has no !testme verdict (last known RED 968). v3 migration status unclear — re-run !testme.
immichv3.0.1 → v3.0.3GREENnonebuild 1130 ✓#4THIS week's only new upgrade: stacks v3.0.2+v3.0.3 patches on last week's PR, one small TypeORM migration ran clean. valkey:9 digest refreshed to v3.0.3's pin; postgres unchanged. GREEN at 1130. Close stray sweep #3.
matrix-synapsesynapse v1.155.0 → v1.156.0 (+MAS 1.20)GREENnonebuild 1125 ✓#5synapse v1.155.0→v1.156.0 + MAS 1.19→1.20; extends bridge work (signal/telegram, bridge DBs 13→14). Dump/restore each bridge DB before deploy. GREEN at 1125.
mattermost-lts10.11.20 → 11.7.6 (ESR)GREENnonebuild 1124 ✓#210.11.20→11.7.6 ESR (low–med security). 10.11 ESR support ends 15 Aug 2026. pg held at 15. Note v11 free-offering limits. GREEN at 1124. Fix PR #1 folded into #2.
gitea1.26.2 → 1.26.4-rootlessGREENnonebuild 1118 ✓#51.26.2→1.26.4-rootless (security: don't auto-reactivate disabled users on OAuth callback; 1.26.3 skipped). pg held at 15. 1.27.0 deferred. GREEN at 1118. Reconcile fix #4 (no CI).
mailu2024.06.52 → 2024.06.54GREENnonebuild 1123 ✓#52024.06.52→2024.06.54 (.53 fixes vacation-sieve injection via display name; .54 admin-UI form bugs). No schema/config changes. GREEN at 1123. Reconcile backup-labels #3 (GREEN 483).
n8n2.28.2 → 2.31.0GREENnonebuild 1129 ✓#52.28.2→2.31.0 (blocked hostnames, Entra SP, MCP tools, unified N8N_WEBHOOK_URL, Kafka mTLS). No breaking changes; migrations auto-run. GREEN at 1129.
ghost6.50.0 → 6.52.1-alpineGREENnonebuild 1116 ✓#76.50.0→6.52.1-alpine (Social Web handle prefs, Stripe tax-ID, Source v1.7.1/Casper v5.12.1; Tenor GIF removed). mysql held 8.4 LTS. GREEN at 1116. Close stray sweep #6.
hedgedocpg 17 → 18-alpineGREENnonebuild 977 ✓#3db pgautoupgrade 17→18-alpine + PGDATA pin (18-alpine moved PGDATA; pin prevents data loss). app 1.11.0 unchanged. GREEN at 977. Close stray probe #1.
custom-html-tinygit v2.52.0 → v2.54.0GREENnonebuild 971 ✓#9alpine/git v2.52.0→v2.54.0 on the optional git-pull cronjob overlay (git 2.53/2.54). App image unchanged. GREEN at 971. Close stray sweep #8.
bluesky-pds0.4.219 → 0.4.5009GREENnonebuild 970 ✓#3pds 0.4.219→0.4.5009 (Node 20→24, index.js→index.ts, @atproto/pds 0.5.9). No env/secret/migration changes. GREEN at 970 (head unchanged since 06-26). Reconcile fix #4 (no CI).
cryptpadUPTODATEnoneUp-to-date. No open PR this week.
droneUPTODATEnoneUp-to-date. No open PR.
libredeskUPTODATEnoneUp-to-date. No open PR.
uptime-kumaUPTODATEnoneUp-to-date (external — maintained elsewhere; a prior upgrade merged). No open PR.
mumbleUPTODATEnone#1Up-to-date. Only a lingering cfold-sweep probe PR #1 (build 732, GREEN) — not an upgrade, can be closed.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

keycloak 26.7.0 — four security fixes on the identity provider (high)
keycloak 26.6.4 → 26.7.0 is a minor security release carrying four fixes — CVE-2026-9796 (admin role-rename TOCTOU lets a manage-clients user escalate realm-wide), CVE-2026-9689 (HTTP Parameter Pollution in the OIDC redirect URI allows response-parameter duplication), CVE-2026-9798 (the CIBA authentication flow bypasses brute-force account lockout) and CVE-2026-11986 (FGAP v1 lets a user unassign any role) — plus a Quarkus bump. As the identity provider fronting other services, keycloak is the highest-priority merge of the week. All new features are opt-in; the three removed niche features (Twitter IDP, token-exchange-external-internal:v2, persistent-sessions batching) are not in the recipe's default config, so no config changes. !testme GREEN at build 1120 — open and overdue to merge.
nginx 1.31.1 → 1.31.2 — memory-safety CVE batch (high) · custom-html
The nginx 1.31.1 → 1.31.2 patch closes three memory-safety CVEs: CVE-2026-42530 (a QUIC use-after-free), CVE-2026-42055 (an HTTP/2 heap buffer overflow) and CVE-2026-48142 (a charset_map overread). It ships GREEN in custom-html (PR #5, build 969), bundled with an alpine/git v2.52.0 → v2.54.0 sidecar bump. custom-html uses nginx for static-file serving, where the affected modules are not exercised, but the memory-safety fixes are worth taking regardless. This PR has been open and GREEN since the 07-03 run — overdue to merge.

What changed

26.6.4 → 26.7.0. A minor security release: four CVE fixes (admin-role TOCTOU escalation, OIDC redirect-param pollution, CIBA brute-force bypass, FGAP role unassign) plus a Quarkus bump; MariaDB held at 12.3. All new features opt-in; the three removed niche features aren't in the default config, so no config changes. GREEN at build 1120 — open and overdue to merge.
nginx 1.31.1 → 1.31.2 brings the memory-safety CVE batch (QUIC UAF, HTTP/2 heap overflow, charset_map overread); alpine/git bumped v2.52.0 → v2.54.0. linuxserver/openssh-server left at its intentional latest pin. GREEN at build 969 — the leftover 07-03 PR, re-confirmed GREEN; merge it to land the nginx CVE fixes.
collabora 25.04.9.4.1 → 26.04.2.1.1 (CODE 25.04 → 26.04 year-line) and onlyoffice 9.3.1.2 → 9.4.1.2 (9.4 backend consolidation, internal-only). Both tags are abra-unparseable so were hand-edited. RED at build 984: the first failure was the host disk running full, but the latest run is still red and needs a real diagnosis before merge. Companion regall-sweep PR #3 (build 749) can be closed.
PR #5 was rebased from the v2.0.0 → v3.2.1 + ClickHouse 23.4 → 24.12 jump to a small 'revert: restore sleep 10 (needed for the pgautoupgrade window)'. The current head carries no !testme verdict (last known RED at build 968); the v3 migration's status is unclear — re-run !testme to get a current verdict.
app 3.5.3 → 2026.1.5 (the calver ESR line; 239 changes incl. 18 security, plus 11 more in 2026.1.5) + redis 7.4 → 8.8-alpine (8.0.2–8.0.6 CVE fixes; 7.x RDB loads cleanly). db postgres:pg18 left as-is. RED at build 1117 on two stale cc-ci tests (a hardcoded 3.5.3 image assertion, and a stale bitnami base the chaos redeploy can't migrate from). The upgrade itself is chaos-verified correct. Four open PRs to reconcile: #6 upgrade, #8 stack-prefixed hostnames fix, #5 official-image switch, #1 bitnami→bitnamilegacy re-pin.
impress v5.3.0 → v5.4.1 (carried on PR #7 alongside the prior nginx 1.31.2 + minio 2025-09-07 bumps). v5.4.0 deliberately removed DRF Bearer-token auth — the API now uses cookie sessions only — which is the new correct behavior; the stale OIDC test asserts the old Bearer flow. All lifecycle tiers pass; RED at build 1121 is the single stale test. (minio has a GitHub-only CVE patch that was never published as a container image; repo archived, recipe pinned to newest available 2025-09.)
meet v1.21.0 → v1.23.0 (recording egress fallback, PiP cap, summary API v2 migration, analytics) + livekit v1.13.1 → v1.13.3. v1.22.0 rejects user access tokens on the API — a security hardening that breaks the stale functional test (it uses a Bearer token). All lifecycle tiers pass; RED at build 1122 is that one stale test.
v3.0.1 → v3.0.3 (this week's only new upgrade): stacks the v3.0.2 (2026-07-09) + v3.0.3 (2026-07-15) patch/bugfix releases on top of last week's v3.0.2 PR — no breaking changes, one small TypeORM migration (1782500000000-RestoreLivePhotoStillVisibility) ran cleanly. immich-server + immich-machine-learning plain-tag bumped; valkey:9 digest refreshed to immich v3.0.3's own compose pin; postgres 14-vectorchord unchanged (no pg-major migration). abra FATAs on the tag+digest pins, so image edits are hand-edits. GREEN at build 1130. Companion regall-sweep PR #3 (build 745) can be closed.
synapse v1.155.0 → v1.156.0 (MSC4354 Sticky Events, MSC2409 ephemeral events, MSC4140 delayed-event auth) + MAS 1.19 → 1.20 (client IP tracking, device-auth-grant). Extends PR #5's bridge work (signalbridge v0.2606.0, telegram Go-bridgev2 config rewrite, bridge DBs 13 → 14-alpine). No breaking changes. Operators with existing bridge data must dump/restore each plain-postgres bridge DB before deploying. GREEN at build 1125. (abra's calver blind spot: mautrix/signal v26.02.2 is parsed as newer than v0.2606.0, so the bump is hand-verified.)
10.11.20 → 11.7.6 ESR — a major ESR jump carrying low–medium security fixes. 10.11 ESR security support ends 15 Aug 2026, so this is the migration to make. postgres held at 15-alpine (a major pg bump is a separate operator-guided dump/restore). Note v11 free-offering changes (Entry 50-user / Team 250-user limits, GitLab SSO removed from Team edition). GREEN at build 1124. The backup-restore fix PR #1 is folded into #2.
1.26.2 → 1.26.4-rootless: a patch carrying a security fix (don't auto-reactivate disabled users on the OAuth2 callback, #38009) and a git-log context error fix; 1.26.3 is skipped (a 'context deadline exceeded' regression). postgres 15 held — a major bump needs an operator dump/restore. 1.27.0 (released the same day, with breaking CSP / reusable-workflow changes) is deliberately deferred to a dedicated minor-bump run. GREEN at build 1118. Reconcile with the app.ini-writable fix PR #4 (no CI).
2024.06.52 → 2024.06.54 across all six mailu/* services. 2024.06.53 fixes vacation/reply sieve injection via the account display name; 2024.06.54 fixes two admin-UI form-flow bugs. Patch bug-fixes, no schema/config changes. GREEN at build 1123. Reconcile with the backupbot-labels PR #3 (GREEN build 483).
2.28.2 → 2.31.0, spanning 2.29 (configurable blocked hostnames, Entra Service Principal, MCP workflow history tools, Slack schedule message) and 2.30 (unified N8N_WEBHOOK_URL, Kafka mTLS, Excel/Teams Service Principal auth), plus 2.30.x–2.31.x bugfixes. No breaking changes; DB migrations auto-run on startup. GREEN at build 1129.
6.50.0 → 6.52.1-alpine: Social Web handle preferences, Stripe tax-ID collection when automatic tax enabled, Source v1.7.1 + Casper v5.12.1, and a 6.52.1 automations email-editor link-selection fix. 6.52.0 removed the discontinued Tenor GIF provider (admin UI only). mysql held at 8.4 LTS — Ghost only certifies mysql 8.x. GREEN at build 1116. Companion regall-sweep PR #6 (build 744) can be closed.
db pgautoupgrade 17 → 18-alpine with a PGDATA=/var/lib/postgresql/data pin — 18-alpine moved its default PGDATA to /var/lib/postgresql/18/docker, so without the pin a plain tag bump fresh-inits an ephemeral cluster and the 17 data is lost. The pin restores the volume mount. app hedgedoc 1.11.0 unchanged. cc-ci's !testme exercises the sqlite backend, so the postgres override is verified in the step-2b direct deploy (16→17→18 clean). GREEN at build 977. Companion generic-suite probe PR #1 (build 608) can be closed.
alpine/git v2.52.0 → v2.54.0 on the optional git-pull cronjob overlay (bundles git 2.53/2.54: a new experimental git history command, geometric repack default). The app image (joseluisq/static-web-server 2.43.0) is unchanged. No clone/fetch/pull behavior change. GREEN at build 971. Companion regall-sweep PR #8 (build 752) can be closed.
pds 0.4.219 → 0.4.5009, spanning the Node 20 → 24 + index.js → index.ts restructure (entrypoint v1 → v2) through @atproto/pds 0.5.9 (resilient background queue, undici v8, pino v10). No env/secret/migration changes across the whole journey. 0.4.5009 is still the newest upstream tag; head unchanged since 06-26, re-verified GREEN at build 970. Reconcile with the routing-rename fix PR #4 (no CI).