Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of July 24, 2026report.ci.commoninternet.net2026-07-24 13:23 UTC

Twenty recipes considered; ten upgrades are !testme GREEN and merge-ready, two (lasuite-docs and lasuite-meet) are RED on stale cc-ci tests — and both carry this week's nginx 1.31.3 CVE batch, so the security fix is blocked behind a needed --with-tests re-run — the rest are up-to-date. Address the nginx 1.31.3 batch first: three CVEs (a map-regex heap overflow, an uninitialized-memory disclosure, and an SSI use-after-free) land across five recipes, three of them green. Then mailu's X-Forwarded-By advisory (internet-facing mail) and the mattermost 11.7.7 ESR security patch. One operational snag: the upgrader stalled mid-run when its opencode provider stopped accepting requests; the supervisor recovered the last four recipes on the opencode-go provider.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
custom-html1.13.0+1.31.1 → 1.14.0+1.31.3GREEN3build 1132 ✓#5nginx 1.31.2 → 1.31.3 security patch (CVE-2026-42533/60005/56434) + alpine/git v2.54.0, folded onto the existing evolving PR #5 (which already carried 1.31.1→1.31.2). Static-file recipe — a drop-in. Highest-value merge of the week.
matrix-synapse0.6.0+v1.156.0 → 0.7.0+v1.157.1GREEN3build 1142 ✓#5synapse v1.157.1 (v1.157.0 removes the legacy MSC3861 flow — no-op here, recipe already on MAS), MAS 1.21.0, mautrix signal+telegram v0.2607.0, nginx 1.31.3 CVE batch. All postgres held at 14-alpine (operator decision).
lasuite-drive0.11.0+v0.19.0 → 0.12.0+v0.20.0GREEN3build 1139 ✓ (run 2)#6drive v0.20.0 (×4 services) + nginx 1.31.3 CVE batch + onlyoffice 9.3.1.2→9.4.1.2. collabora REVERTED to 25.04.9.4.1 — every 26.04.2.x head crash-loops ("sh not found in $PATH"); see Addendum. Run 1 was killed (collabora 26.x hung), run 2 green.
lasuite-docs0.3.5+v5.2.1 → 0.3.6+v5.4.1STALE3RED 1136 · stale tests#7web nginx 1.31.3 CVE batch (impress v5.4.1 + minio 2025-09-07 carried). RED on 2 stale Bearer-auth tests — impress v5.4.0 removed Bearer-auth; the cc-ci tests assert pre-v5.4.0 behaviour. Not a recipe regression — re-run /recipe-upgrade lasuite-docs --with-tests.
lasuite-meet0.5.0+v1.21.0 → 0.6.0+v1.24.0STALE3RED 1137 · stale tests#8meet v1.24.0 (×3), livekit v1.13.4, nginx 1.31.3 CVE batch. RED on test_create_room_get_livekit_token — meet v1.22.0+ rejects raw OIDC user tokens as Bearer; the test asserts pre-v1.22 behaviour. Not a regression — re-run --with-tests.
mailu3.1.1+2024.06.52 → 3.1.2+2024.06.55GREEN1build 1144 ✓#5All six mailu images 2024.06.52 → 2024.06.55; 2024.06.55 fixes GHSA-rfhj-4wcq-74xg (X-Forwarded-By not set). Internet-facing mail — prioritise. redis + certdumper held. (Summary cites build #1141; the fresh live verdict is #1144.)
mattermost-lts2.1.11+10.11.19 → 2.2.0+11.7.7GREENnonebuild 1143 ✓#211.7 ESR security patch (11.7.6 → 11.7.7) — Mattermost discloses "Low to High severity security fixes" with no CVE ids. postgres held at 15-alpine. Reconcile with fix PR #1 (restore re-import). Note: 10.11 ESR security support ends 2026-08-15.
keycloak10.8.1+26.6.4 → 10.9.0+26.7.0GREENnonebuild 1135 ✓#5Identity provider 26.6.4 → 26.7.0 minor (Quarkus 3.33.2.1). DB auto-migrates on boot — back up MariaDB first. Twitter/X IDP removed; KEYCLOAK_ADMIN + KC_PROXY=edge deprecated (still work). mariadb held at 12.3.
gitea3.6.1+1.26.2-rootless → 3.7.0+1.27.0-rootlessGREENnonebuild 1134 ✓#51.26.2 → 1.27.0 (via 1.26.4, already on the branch: security — don't auto-reactivate disabled users on OAuth2 callback). 1.27.0 is BREAKING: reusable-workflow syntax (#37478) + CSP script-nonce (#37232, gates inline JS — custom HTML/themes reconcile). postgres held at 15.18.
ghost1.4.0+6.45.0-alpine → 1.5.0+6.53.0-alpineGREENnonebuild 1133 ✓#7ghost 6.52.1-alpine → 6.53.0-alpine (boot-time adapter validation, sso DI, anti-spam signup hardening). mysql held at 8.4 (9.x not supported by Ghost). No schema migration. Ready to merge.
n8n3.4.0+2.25.3 → 3.5.0+2.32.4GREENnonebuild 1140 ✓#5n8n 2.31.0 → 2.32.4 (Instance AI / AI Agent builder + core bugfixes; no breaking changes, no env renames, no manual migration). pgautoupgrade held at 18-alpine. Clean.
bluesky-pds0.3.0+0.4.219 → 0.3.1+0.4.5009GREENnonebuild 1131 ✓#3pds 0.4.219 → 0.4.5009 (Node 24 + run-TS-directly runtime jump from v0.4.5001; 0.4.5006/5009 patches). caddy:2 unchanged. No env/schema change. Reconcile with open fix PR #4 (rename service app→pds for shared-proxy caddy).
immichv3.0.1 → v3.0.3SKIPPEDnonebuild 1130 ✓ · PR#4#4Up-to-date — no new upgrade this week. abra can't parse immich's tag+digest-pinned postgres/valkey images (blind spot), so it's skipped from the survey even though existing PR #4 already tracks v3.0.3 (GREEN at build 1130). Stale regall PR #3 lingers.
discourseUPTODATEnoneRED 1117 · PR#6#6Skipped — up-to-date this week. Yet four open PRs linger, including a RED prior-run upgrade PR #6 (3.5.3 → 2026.1.5, redis 7.4 → 8.8). Plus #8 (stack-prefixed hostnames), #5 (official discourse image), #1 (bitnami→bitnamilegacy re-pin). Operator decision on which land.
custom-html-tinyUPTODATEnonebuild 971 ✓ · PR#9#9Up-to-date — no new upgrade this week. Two leftover open PRs to triage: #9 (alpine/git v2.54.0, green #971) and #8 (regall sweep, green #752).
hedgedocUPTODATEnonebuild 977 ✓ · PR#3#3Up-to-date this week. Leftover open PR #3 (pgautoupgrade → 18-alpine, pin PGDATA, green #977) + #1 (generic-suite probe, green #608).
plausibleUPTODATEnonePR#5 · no CI#5Up-to-date this week (last week's RED clickhouse crash-loop is gone from the survey). Open fix PR #5 (revert a removed sleep 10 needed for the pgautoupgrade window) has no CI verdict yet — worth an operator look before next week's upgrade.
cryptpadUPTODATEnoneUp-to-date. No open PR.
droneUPTODATEnoneUp-to-date. No open PR.
mumbleUPTODATEnonebuild 732 ✓ · PR#1#1Up-to-date. Lingering open PR #1 (cfold sweep probe, green #732) — can be closed.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

nginx 1.31.3 — heap overflow, memory disclosure, SSI use-after-free (high) · custom-html, matrix-synapse, lasuite-drive (+ lasuite-docs, lasuite-meet blocked)
The nginx 1.31.2 → 1.31.3 mainline patch (15 Jul 2026) closes three CVEs: CVE-2026-42533 (heap buffer overflow in map with regex matching when the map variable is used in a string expression after an affected capture), CVE-2026-60005 (uninitialized-memory access with unnamed regex captures + the slice directive / background cache update → memory disclosure or worker termination), and CVE-2026-56434 (use-after-free processing a crafted proxied backend response in ngx_http_ssi_filter_module). It also bounds HTTP/2 response header/trailer sizes by proxy_buffer_size/grpc_buffer_size and disables external entities in the xslt filter — neither of which affects these recipes' standard reverse-proxy / static-server configs, so it's a drop-in. GREEN this week in custom-html (build 1132), matrix-synapse (1142) and lasuite-drive (1139). The same batch is also bundled into lasuite-docs (#7) and lasuite-meet (#8), but those two are RED on stale cc-ci tests — the security fix there is blocked behind a needed --with-tests re-run (see Addendum). Highest-value merges of the week.
mailu — GHSA-rfhj-4wcq-74xg, X-Forwarded-By not set (high) · internet-facing mail
mailu 2024.06.52 → 2024.06.55 rolls up three patch releases; 2024.06.55 (18 Jul) is the security one — it ensures X-Forwarded-By is set (advisory GHSA-rfhj-4wcq-74xg). 2024.06.53 fixes a sieve injection via vacation-reply display names containing special characters; 2024.06.54 fixes two admin-UI form-flow bugs. All six mailu images (front/admin/imap/smtp/antispam/webmail) move in lockstep; redis and certdumper held. No breaking changes — patch-level within the 2024.06 stable line. Webmail and the SMTP/IMAP front are internet-facing, so prioritise this merge. !testme GREEN at build 1144.
mattermost-lts 11.7.7 ESR — Low-to-High security fixes (severity undisclosed) · ESR patch
mattermost 11.7.6 → 11.7.7 is an Extended Support Release security patch. Mattermost's release body states only that it "contains Low to High severity level security fixes" — upstream discloses no CVE ids publicly for ESR patches, so the exact count isn't enumerable here. No migrations, no breaking config changes — standard rolling upgrade. postgres held at 15-alpine. Two adjacent notes: (1) the previous ESR line 10.11.x loses security support on 2026-08-15 — migrate any 10.11 deployment to 11.7 before then; (2) reconcile this upgrade PR #2 with the open restore-fix PR #1. !testme GREEN at build 1143.

What changed

nginx 1.31.2 → 1.31.3 security patch (CVE-2026-42533/60005/56434) folded onto the existing evolving PR #5, which already carried the 1.31.1 → 1.31.2 step plus alpine/git v2.52.0 → v2.54.0. A single compose-image bump for a static-file recipe — drop-in, no config change. Recommended release: abra recipe release custom-html -z.
synapse v1.156.0 → v1.157.1, MAS 1.20.0 → 1.21.0, mautrix signal + telegram bridges v0.2606.0 → v0.2607.0, web nginx 1.31.2 → 1.31.3 (the CVE batch). v1.157.0 removes the experimental MSC3861 auth-delegation flow — a no-op here because the recipe already uses stable MAS; operators still on legacy experimental_oidc / MSC3861 must finish that move first. MAS 1.21.0 and the bridge bumps are bugfix-only. All postgres (db + bridge dbs) held at 14-alpine — major jumps are an operator decision. Recommended release: abra recipe release matrix-synapse -y.
drive v0.19.0 → v0.20.0 across app/backend/celery/celery-beat (additive features + bugfixes, no breaking changes; Django migrations auto-run via AUTO_MIGRATIONS), nginx 1.31.2 → 1.31.3 (CVE batch), onlyoffice 9.3.1.2 → 9.4.1.2. The notable gotcha is collabora: PR #6 reverts it to upstream-published 25.04.9.4.1 because every 26.04.2.x head crash-loops under the recipe's entrypoint: sh -c "…" (exec: "sh": not found in $PATH) — a swarm-compose deploy quirk, not an image bug per se. The run needed two !testme attempts: run 1 (collabora 26.x) was killed past the 60-min drone budget; run 2 (with the revert) is green. Operator should revisit collabora separately. Recommended release: abra recipe release lasuite-drive -y.
web nginx 1.31.2 → 1.31.3 security bump (CVE-2026-42533/60005/56434), extended onto PR #7 which already carries the bigger delta from upstream main: impress v5.2.1 → v5.4.1 (frontend/backend/celery/y-provider) and minio RELEASE.2025-05-24 → 2025-09-07 (minio upstream archived Apr 2026; this is the newest tag). DB migrations auto-run. The catch: !testme is RED (build 1136) on two stale Bearer-auth cc-ci tests — impress v5.4.0 removed Bearer-auth, which the tests still assert. Not a recipe regression; re-run /recipe-upgrade lasuite-docs --with-tests to update the cc-ci tests. The nginx CVE fix itself is sound and deploy-ready; it's just gated behind the test update. Recommended release (post test-fix + merge): abra recipe release lasuite-docs -z.
meet v1.21.0 → v1.24.0 (three minor feature releases across app/backend/celery), livekit-server v1.13.1 → v1.13.4, web nginx 1.31.2 → 1.31.3 (CVE batch). No breaking changes for the standalone recipe (AUTO_MIGRATIONS handles the DB); an optional new env AUTHENTICATED_PARTICIPANTS_CAN_EDIT_DISPLAY_NAME defaults true. The catch: !testme is RED (build 1137) on test_create_room_get_livekit_token_and_read_back — meet v1.22.0+ rejects raw OIDC user access tokens as Bearer, which the test still uses. Same diagnosis as the prior run #1122 at v1.23.0. Not a regression; re-run /recipe-upgrade lasuite-meet --with-tests. The nginx CVE fix is gated behind the test update. Recommended release: abra recipe release lasuite-meet -y.
All six mailu service images 2024.06.52 → 2024.06.55 (front/admin/imap/smtp/antispam/webmail). 2024.06.55 is the security fix (GHSA-rfhj-4wcq-74xg — X-Forwarded-By now set); 2024.06.53 fixes a sieve injection via vacation-reply display names with special characters; 2024.06.54 fixes two admin-UI form-flow bugs. redis (8.8.0-alpine) and certdumper (v2.11.4) held. Patch-level within the 2024.06 stable line — no DB migrations, no compose/env changes, only image tags moved. Internet-facing mail — prioritise. Recommended release: abra recipe release mailu -z.
11.7.6 → 11.7.7 — the next ESR security patch on the 11.7.x line (ESR through ~15 May 2027). Upstream states "Low to High severity security fixes" with no CVE ids disclosed. No migrations, no breaking config — standard rolling upgrade. postgres held at 15-alpine (16/17/18 are an operator-guided major migration). The PR also carries the restore re-import fix (pg_backup.sh / gzip-backup), so it overlaps fix PR #1 — reconcile before release. Recommended release: abra recipe release mattermost-lts -z.
26.6.4 → 26.7.0 minor (Quarkus 3.33.2.1). DB auto-migrates on boot via the Liquibase JPA updater (KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update) — back up the MariaDB volume before deploying as a precaution. No compose/config changes; all 26.7.0 features are opt-in flags disabled by default. Deprecations to plan for (non-blocking in 26.7.0): KEYCLOAK_ADMIN/KEYCLOAK_ADMIN_PASSWORD → KC_BOOTSTRAP_ADMIN_*, Hostname-v1 KC_PROXY=edge → v2. Removed: token-exchange-external-internal:v2 and the Twitter/X IDP (legacy twitter-broker:v1 shim remains for now) — operators relying on Twitter/X login should migrate. mariadb held at 12.3. Recommended release: abra recipe release keycloak -y.
1.26.2 → 1.27.0 on the existing PR #5, via the intermediate 1.26.4 already on the branch (which adds the security fix: do not auto-reactivate disabled users on OAuth2 callback; 1.26.3 was skipped upstream — regression #38177). 1.27.0 is BREAKING at the app level: reusable-workflow syntax changes (#37478, affects only deployments using Gitea Actions + reusable workflows — review YAML before upgrading) and a Content-Security-Policy script-nonce (#37232 — gates inline JS; custom header/footer/org HTML/themes with inline <script> may need a nonce; default deployments need no action; reverse proxies that also set a CSP should reconcile). Also adds X-Content-Type-Options: nosniff by default and an AWS Cognito OAuth2 provider. postgres held at 15.18 (no pg_upgrade). Recommended release: abra recipe release gitea -y.
ghost 6.52.1-alpine → 6.53.0-alpine — minor feature/bugfix release (boot-time adapter validation, sso user-lookup DI, anti-spam signup hardening, analytics bucketing fixes, welcome-email-editor unsaved-warning + expired-session fixes). No DB migration, no config/env change beyond the image tag. mysql held at 8.4 — 9.x is not supported by Ghost (removes mysql_native_password, enforces inline FK specs); a 9.x move is an operator decision, not a weekly cron bump. Recommended release: abra recipe release ghost -y.
n8n 2.31.0 → 2.32.4 across the existing PR #5. 2.32.0 is a minor (Instance AI / AI Agent builder + core bugfixes across AI assistant, MCP servers, durable scheduler, credentials, AWS/SES signing); 2.32.1–2.32.4 are patch bugfixes. No breaking changes, no N8N_* env renames, no required manual migration — TypeORM DB migrations 17840000000015–1784000030 ran cleanly on boot in the dev deploy. pgautoupgrade held at 18-alpine. Clean. Recommended release: abra recipe release n8n -y.
pds 0.4.219 → 0.4.5009. The big jump was v0.4.5001 (2026-05-30): a new versioning scheme (base 0.4 . minor patch padded-3), Node 24, and the service restructured to run TypeScript directly (/app/index.ts, no index.js) — @atproto/pds 0.5.1 underneath, already validated GREEN in upgrade PR #3 last month. 0.4.5006 and 0.4.5009 are patch bumps with no schema/env changes. caddy:2 unchanged. Env interface unchanged across 0.4.x; no DB migration. A minor recipe release (-y) is recommended because of the Node-24 / runtime jump. Reconcile with the open routing fix PR #4 (rename main service app → pds so caddy resolves this stack on a shared proxy). Recommended release: abra recipe release bluesky-pds -y.