Co-op Cloud Recipe CI · Weekly Edition
The Recipe Report
Week of July 17, 2026report.ci.commoninternet.net2026-07-17 02:41 UTC
Nothing was merged this week, so the priority picture is unchanged: merge the two high-severity CVE PRs first — keycloak 26.7.0 (four CVEs on the identity provider) and custom-html's nginx 1.31.2 (three memory-safety CVEs), both !testme GREEN and open since the 07-03/07-13 runs. The /upgrade-all run itself was quiet — 19 of 20 recipes already up-to-date, the only new upgrade immich v3.0.2 → v3.0.3 (a patch, GREEN at build 1130). Then unblock discourse, lasuite-docs and lasuite-meet — RED only because an upstream API-auth hardening broke cc-ci's OIDC test fixtures, not the upgrades — diagnose lasuite-drive's genuine collabora/onlyoffice RED, and clear the routine GREEN bumps.
The full wire — every recipe, in priority order
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|
| keycloak | 26.6.4 → 26.7.0 | GREEN | 4 | build 1120 ✓ | #5 | … | Identity provider — 4 CVE fixes (admin-role TOCTOU, OIDC redirect-param pollution, CIBA brute-force bypass, FGAP role unassign) + Quarkus bump. GREEN since 07-13; overdue to merge. |
| custom-html | nginx 1.31.1 → 1.31.2 + git v2.54.0 | GREEN | 3 | build 969 ✓ | #5 | … | nginx 1.31.1→1.31.2 (3 memory-safety CVEs: QUIC UAF, HTTP/2 heap overflow, charset_map overread) + alpine/git v2.54.0. Open & GREEN since 07-03 — overdue to merge. |
| lasuite-drive | collabora 25.04 → 26.04 · onlyoffice 9.3 → 9.4 | FAILED | none | RED 984 · collabora/onlyoffice | #6 | … | collabora 25.04→26.04 + onlyoffice 9.3→9.4 (both abra-unparseable, hand-edited). RED at 984 — first failure was disk-full, latest still red; needs real diagnosis. Close stray sweep #3. |
| discourse | 3.5.3 → 2026.1.5 (+redis 8.8) | STALE | none | RED 1117 · stale tests | #6 | … | app 3.5.3→2026.1.5 (239 chg incl. 18 security) + redis 7.4→8.8. RED on two stale cc-ci tests (hardcoded 3.5.3 assertion + bitnami base), not the upgrade. 4 open PRs to reconcile (#6,#8,#5,#1). |
| lasuite-docs | impress v5.3.0 → v5.4.1 | STALE | none | RED 1121 · stale OIDC test | #7 | … | impress v5.3.0→v5.4.1. RED at 1121 on one stale OIDC test (v5.4.0 removed Bearer auth for cookie sessions — new correct behavior). Lifecycle tiers pass. minio CVE unfixable (image archived). |
| lasuite-meet | meet v1.21.0 → v1.23.0 (+livekit v1.13.3) | STALE | none | RED 1122 · stale API-auth test | #8 | … | meet v1.21.0→v1.23.0 + livekit v1.13.1→v1.13.3. RED at 1122 on one stale API-auth test (v1.22.0 rejects user access tokens — security hardening). Lifecycle tiers pass. |
| plausible | v2.0.0 → v3.2.1 (+ClickHouse 24.12) | STALE | none | no verdict · re-run !testme | #5 | … | PR #5 rebased from the v2→v3 + ClickHouse 24.12 jump to a small 'restore sleep 10' revert. Current head has no !testme verdict (last known RED 968). v3 migration status unclear — re-run !testme. |
| immich | v3.0.1 → v3.0.3 | GREEN | none | build 1130 ✓ | #4 | … | THIS week's only new upgrade: stacks v3.0.2+v3.0.3 patches on last week's PR, one small TypeORM migration ran clean. valkey:9 digest refreshed to v3.0.3's pin; postgres unchanged. GREEN at 1130. Close stray sweep #3. |
| matrix-synapse | synapse v1.155.0 → v1.156.0 (+MAS 1.20) | GREEN | none | build 1125 ✓ | #5 | … | synapse v1.155.0→v1.156.0 + MAS 1.19→1.20; extends bridge work (signal/telegram, bridge DBs 13→14). Dump/restore each bridge DB before deploy. GREEN at 1125. |
| mattermost-lts | 10.11.20 → 11.7.6 (ESR) | GREEN | none | build 1124 ✓ | #2 | … | 10.11.20→11.7.6 ESR (low–med security). 10.11 ESR support ends 15 Aug 2026. pg held at 15. Note v11 free-offering limits. GREEN at 1124. Fix PR #1 folded into #2. |
| gitea | 1.26.2 → 1.26.4-rootless | GREEN | none | build 1118 ✓ | #5 | … | 1.26.2→1.26.4-rootless (security: don't auto-reactivate disabled users on OAuth callback; 1.26.3 skipped). pg held at 15. 1.27.0 deferred. GREEN at 1118. Reconcile fix #4 (no CI). |
| mailu | 2024.06.52 → 2024.06.54 | GREEN | none | build 1123 ✓ | #5 | … | 2024.06.52→2024.06.54 (.53 fixes vacation-sieve injection via display name; .54 admin-UI form bugs). No schema/config changes. GREEN at 1123. Reconcile backup-labels #3 (GREEN 483). |
| n8n | 2.28.2 → 2.31.0 | GREEN | none | build 1129 ✓ | #5 | … | 2.28.2→2.31.0 (blocked hostnames, Entra SP, MCP tools, unified N8N_WEBHOOK_URL, Kafka mTLS). No breaking changes; migrations auto-run. GREEN at 1129. |
| ghost | 6.50.0 → 6.52.1-alpine | GREEN | none | build 1116 ✓ | #7 | … | 6.50.0→6.52.1-alpine (Social Web handle prefs, Stripe tax-ID, Source v1.7.1/Casper v5.12.1; Tenor GIF removed). mysql held 8.4 LTS. GREEN at 1116. Close stray sweep #6. |
| hedgedoc | pg 17 → 18-alpine | GREEN | none | build 977 ✓ | #3 | … | db pgautoupgrade 17→18-alpine + PGDATA pin (18-alpine moved PGDATA; pin prevents data loss). app 1.11.0 unchanged. GREEN at 977. Close stray probe #1. |
| custom-html-tiny | git v2.52.0 → v2.54.0 | GREEN | none | build 971 ✓ | #9 | … | alpine/git v2.52.0→v2.54.0 on the optional git-pull cronjob overlay (git 2.53/2.54). App image unchanged. GREEN at 971. Close stray sweep #8. |
| bluesky-pds | 0.4.219 → 0.4.5009 | GREEN | none | build 970 ✓ | #3 | … | pds 0.4.219→0.4.5009 (Node 20→24, index.js→index.ts, @atproto/pds 0.5.9). No env/secret/migration changes. GREEN at 970 (head unchanged since 06-26). Reconcile fix #4 (no CI). |
| cryptpad | — | UPTODATE | none | | | | Up-to-date. No open PR this week. |
| drone | — | UPTODATE | none | | | | Up-to-date. No open PR. |
| libredesk | — | UPTODATE | none | | | | Up-to-date. No open PR. |
| uptime-kuma | — | UPTODATE | none | | | | Up-to-date (external — maintained elsewhere; a prior upgrade merged). No open PR. |
| mumble | — | UPTODATE | none | | #1 | … | Up-to-date. Only a lingering cfold-sweep probe PR #1 (build 732, GREEN) — not an upgrade, can be closed. |
Addendum
- Nothing from last week's backlog was merged: the two high-severity CVE PRs — keycloak #5 (4 CVEs, GREEN build 1120) and custom-html #5 (3 memory-safety CVEs, GREEN build 969) — have been open and green since the 07-03/07-13 runs and are overdue to merge. The whole priority picture is unchanged week-on-week.
- Three of the REDs share one root cause and one fix: discourse, lasuite-docs and lasuite-meet are RED only because upstream (discourse's official-image line, lasuite docs v5.4.0, meet v1.22.0) removed Bearer / access-token API auth in favour of cookie sessions — a security hardening that broke cc-ci's OIDC test assertions. The upgrades themselves are chaos-verified correct. Updating the test fixtures to the cookie-session flow would unblock all three at once.
- lasuite-drive is the one genuine RED: collabora 25.04→26.04 + onlyoffice 9.3→9.4 at build 984. The first failure was the host disk running full, but the latest run is still red and has not been touched this week — it needs a real diagnosis before merge.
- plausible is in-flight with no current verdict: PR #5 was rebased from the v2.0.0→v3.2.1 + ClickHouse 23.4→24.12 jump to a small 'revert: restore sleep 10 (needed for the pgautoupgrade window)'. The current head carries no !testme verdict (last known RED at build 968); the v3 migration's status is unclear — re-run !testme to get a current verdict.
- discourse carries four open PRs to reconcile: #6 (upgrade, RED on stale tests), #8 (stack-prefixed hostnames fix, no CI), #5 (official-image switch, no CI) and #1 (bitnami→bitnamilegacy re-pin, no CI). Decide which of the four land.
- Several recipes carry a companion PR alongside the upgrade to reconcile: gitea #4 (app.ini writable-volume fix, no CI), mailu #3 (backupbot labels, GREEN build 483), mattermost-lts #1 (backup-restore fix, GREEN build 901 — now folded into #2) and bluesky-pds #4 (routing-rename fix, no CI).
- A cluster of old non-upgrade sweep / probe PRs linger and can be closed: custom-html-tiny #8 (regall sweep, build 752), ghost #6 (regall sweep, build 744), immich #3 (regall sweep, build 745), lasuite-drive #3 (regall sweep, build 749), hedgedoc #1 (generic-suite probe, build 608) and mumble #1 (cfold sweep probe, build 732). None are upgrades.
- immich's tag+digest pins recurred: abra FATAs on its valkey:9@sha256 and postgres@sha256 pins ('Docker references with both a tag and digest are currently not supported'), so this week's v3.0.2→v3.0.3 bump was resolved via a direct upstream check (docker buildx imagetools inspect + the immich GitHub releases page). Same tooling gap as prior weeks — worth a fix in abra so immich isn't hand-edited every time.
Security Bulletin
🔒 Critical CVE upgrades
keycloak 26.7.0 — four security fixes on the identity provider (high)
keycloak 26.6.4 → 26.7.0 is a minor security release carrying four fixes — CVE-2026-9796 (admin role-rename TOCTOU lets a manage-clients user escalate realm-wide), CVE-2026-9689 (HTTP Parameter Pollution in the OIDC redirect URI allows response-parameter duplication), CVE-2026-9798 (the CIBA authentication flow bypasses brute-force account lockout) and CVE-2026-11986 (FGAP v1 lets a user unassign any role) — plus a Quarkus bump. As the identity provider fronting other services,
keycloak is the highest-priority merge of the week. All new features are opt-in; the three removed niche features (Twitter IDP, token-exchange-external-internal:v2, persistent-sessions batching) are not in the recipe's default config, so no config changes. !testme GREEN at build 1120 — open and overdue to merge.
nginx 1.31.1 → 1.31.2 — memory-safety CVE batch (high) ·
custom-htmlThe nginx 1.31.1 → 1.31.2 patch closes three memory-safety CVEs: CVE-2026-42530 (a QUIC use-after-free), CVE-2026-42055 (an HTTP/2 heap buffer overflow) and CVE-2026-48142 (a charset_map overread). It ships GREEN in
custom-html (PR #5, build 969), bundled with an alpine/git v2.52.0 → v2.54.0 sidecar bump.
custom-html uses nginx for static-file serving, where the affected modules are not exercised, but the memory-safety fixes are worth taking regardless. This PR has been open and GREEN since the 07-03 run — overdue to merge.
What changed
26.6.4 → 26.7.0. A minor security release: four CVE fixes (admin-role TOCTOU escalation, OIDC redirect-param pollution, CIBA brute-force bypass, FGAP role unassign) plus a Quarkus bump; MariaDB held at 12.3. All new features opt-in; the three removed niche features aren't in the default config, so no config changes. GREEN at build 1120 — open and overdue to merge.
nginx 1.31.1 → 1.31.2 brings the memory-safety CVE batch (QUIC UAF, HTTP/2 heap overflow, charset_map overread); alpine/git bumped v2.52.0 → v2.54.0. linuxserver/openssh-server left at its intentional latest pin. GREEN at build 969 — the leftover 07-03 PR, re-confirmed GREEN; merge it to land the nginx CVE fixes.
collabora 25.04.9.4.1 → 26.04.2.1.1 (CODE 25.04 → 26.04 year-line) and onlyoffice 9.3.1.2 → 9.4.1.2 (9.4 backend consolidation, internal-only). Both tags are abra-unparseable so were hand-edited. RED at build 984: the first failure was the host disk running full, but the latest run is still red and needs a real diagnosis before merge. Companion regall-sweep PR #3 (build 749) can be closed.
PR #5 was rebased from the v2.0.0 → v3.2.1 + ClickHouse 23.4 → 24.12 jump to a small 'revert: restore sleep 10 (needed for the pgautoupgrade window)'. The current head carries no !testme verdict (last known RED at build 968); the v3 migration's status is unclear — re-run !testme to get a current verdict.
app 3.5.3 → 2026.1.5 (the calver ESR line; 239 changes incl. 18 security, plus 11 more in 2026.1.5) + redis 7.4 → 8.8-alpine (8.0.2–8.0.6 CVE fixes; 7.x RDB loads cleanly). db postgres:pg18 left as-is. RED at build 1117 on two stale cc-ci tests (a hardcoded 3.5.3 image assertion, and a stale bitnami base the chaos redeploy can't migrate from). The upgrade itself is chaos-verified correct. Four open PRs to reconcile: #6 upgrade, #8 stack-prefixed hostnames fix, #5 official-image switch, #1 bitnami→bitnamilegacy re-pin.
impress v5.3.0 → v5.4.1 (carried on PR #7 alongside the prior nginx 1.31.2 + minio 2025-09-07 bumps). v5.4.0 deliberately removed DRF Bearer-token auth — the API now uses cookie sessions only — which is the new correct behavior; the stale OIDC test asserts the old Bearer flow. All lifecycle tiers pass; RED at build 1121 is the single stale test. (minio has a GitHub-only CVE patch that was never published as a container image; repo archived, recipe pinned to newest available 2025-09.)
meet v1.21.0 → v1.23.0 (recording egress fallback, PiP cap, summary API v2 migration, analytics) + livekit v1.13.1 → v1.13.3. v1.22.0 rejects user access tokens on the API — a security hardening that breaks the stale functional test (it uses a Bearer token). All lifecycle tiers pass; RED at build 1122 is that one stale test.
v3.0.1 → v3.0.3 (this week's only new upgrade): stacks the v3.0.2 (2026-07-09) + v3.0.3 (2026-07-15) patch/bugfix releases on top of last week's v3.0.2 PR — no breaking changes, one small TypeORM migration (1782500000000-RestoreLivePhotoStillVisibility) ran cleanly. immich-server + immich-machine-learning plain-tag bumped; valkey:9 digest refreshed to
immich v3.0.3's own compose pin; postgres 14-vectorchord unchanged (no pg-major migration). abra FATAs on the tag+digest pins, so image edits are hand-edits. GREEN at build 1130. Companion regall-sweep PR #3 (build 745) can be closed.
synapse v1.155.0 → v1.156.0 (MSC4354 Sticky Events, MSC2409 ephemeral events, MSC4140 delayed-event auth) + MAS 1.19 → 1.20 (client IP tracking, device-auth-grant). Extends PR #5's bridge work (signalbridge v0.2606.0, telegram Go-bridgev2 config rewrite, bridge DBs 13 → 14-alpine). No breaking changes. Operators with existing bridge data must dump/restore each plain-postgres bridge DB before deploying. GREEN at build 1125. (abra's calver blind spot: mautrix/signal v26.02.2 is parsed as newer than v0.2606.0, so the bump is hand-verified.)
10.11.20 → 11.7.6 ESR — a major ESR jump carrying low–medium security fixes. 10.11 ESR security support ends 15 Aug 2026, so this is the migration to make. postgres held at 15-alpine (a major pg bump is a separate operator-guided dump/restore). Note v11 free-offering changes (Entry 50-user / Team 250-user limits, GitLab SSO removed from Team edition). GREEN at build 1124. The backup-restore fix PR #1 is folded into #2.
1.26.2 → 1.26.4-rootless: a patch carrying a security fix (don't auto-reactivate disabled users on the OAuth2 callback, #38009) and a git-log context error fix; 1.26.3 is skipped (a 'context deadline exceeded' regression). postgres 15 held — a major bump needs an operator dump/restore. 1.27.0 (released the same day, with breaking CSP / reusable-workflow changes) is deliberately deferred to a dedicated minor-bump run. GREEN at build 1118. Reconcile with the app.ini-writable fix PR #4 (no CI).
2024.06.52 → 2024.06.54 across all six
mailu/* services. 2024.06.53 fixes vacation/reply sieve injection via the account display name; 2024.06.54 fixes two admin-UI form-flow bugs. Patch bug-fixes, no schema/config changes. GREEN at build 1123. Reconcile with the backupbot-labels PR #3 (GREEN build 483).
2.28.2 → 2.31.0, spanning 2.29 (configurable blocked hostnames, Entra Service Principal, MCP workflow history tools, Slack schedule message) and 2.30 (unified N8N_WEBHOOK_URL, Kafka mTLS, Excel/Teams Service Principal auth), plus 2.30.x–2.31.x bugfixes. No breaking changes; DB migrations auto-run on startup. GREEN at build 1129.
6.50.0 → 6.52.1-alpine: Social Web handle preferences, Stripe tax-ID collection when automatic tax enabled, Source v1.7.1 + Casper v5.12.1, and a 6.52.1 automations email-editor link-selection fix. 6.52.0 removed the discontinued Tenor GIF provider (admin UI only). mysql held at 8.4 LTS — Ghost only certifies mysql 8.x. GREEN at build 1116. Companion regall-sweep PR #6 (build 744) can be closed.
db pgautoupgrade 17 → 18-alpine with a PGDATA=/var/lib/postgresql/data pin — 18-alpine moved its default PGDATA to /var/lib/postgresql/18/docker, so without the pin a plain tag bump fresh-inits an ephemeral cluster and the 17 data is lost. The pin restores the volume mount. app
hedgedoc 1.11.0 unchanged. cc-ci's !testme exercises the sqlite backend, so the postgres override is verified in the step-2b direct deploy (16→17→18 clean). GREEN at build 977. Companion generic-suite probe PR #1 (build 608) can be closed.
alpine/git v2.52.0 → v2.54.0 on the optional git-pull cronjob overlay (bundles git 2.53/2.54: a new experimental git history command, geometric repack default). The app image (joseluisq/static-web-server 2.43.0) is unchanged. No clone/fetch/pull behavior change. GREEN at build 971. Companion regall-sweep PR #8 (build 752) can be closed.
pds 0.4.219 → 0.4.5009, spanning the Node 20 → 24 + index.js → index.ts restructure (entrypoint v1 → v2) through @atproto/pds 0.5.9 (resilient background queue, undici v8, pino v10). No env/secret/migration changes across the whole journey. 0.4.5009 is still the newest upstream tag; head unchanged since 06-26, re-verified GREEN at build 970. Reconcile with the routing-rename fix PR #4 (no CI).