Co-op Cloud Recipe CI · Weekly Edition
The Recipe Report
Week of August 3, 2026report.ci.commoninternet.net2026-08-04 16:58 UTC
A recovery run after two provider-side interruptions: the 2026-08-03 pass upgraded 15 of 20 recipes — twelve !testme GREEN, three RED on a cc-ci harness regression (not the recipes) — but the ccci-bridge was broken all run, its stale gitea-bot swarm secret silently dropping every !testme, so every verification went through a Drone-direct workaround. Fix the bridge first (rotate the stale secrets), then merge the security batch: matrix-synapse v1.157.2 ships eleven advisories, the nginx 1.31.3 + redis 8.8.1 CVE bumps land across the La Suite recipes, keycloak carries four CVEs, and mailu rolls up two Roundcube webmail fixes.
The full wire — every recipe, in priority order
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|
| matrix-synapse | v1.157.1 → v1.157.2 | GREEN | 11 | build 1196 ✓ | #5 | … | Security release — 11 ELEMENTSEC advisories (6 high, 3 moderate, 2 low) + mautrix-telegram v0.2607.0. MAS 1.21.0 + nginx 1.31.3 already in upstream main. All postgres DBs held at 13-alpine. Ready to merge. |
| lasuite-docs | v5.2.1 → v5.4.1 | GREEN | 4 | build 1185 ✓ | #7 | … | nginx 1.31.1 → 1.31.3 (3 CVEs) + redis 8.8.0 → 8.10.0 (superset of 8.8.1 RCE fix) + impress v5.4.1 (Bearer-auth removal hardening). AUTO_MIGRATIONS handles DB. Ready to merge. |
| lasuite-meet | v1.21.0 → v1.24.0 | GREEN | 4 | build 1190 ✓ | #8 | … | nginx 1.31.2 → 1.31.3 (CVE batch) + redis 8.8.0 → 8.8.1 (RedisBloom/TDigest RCE) + meet v1.24.0 + livekit v1.13.5. Stale meeting-flow test fixed + merged (cc-ci PR #13). Ready to merge. |
| custom-html-tiny | 2.43.0 → 2.44.0 | GREEN | 4 | build 1162 ✓ | #10 | … | static-web-server 2.44.0 — 4 security advisories (max Moderate) + LTS move. Fresh sws-only PR; overlaps with PR #9 (operator decides). Git bump stays on PR #9. |
| keycloak | 26.6.4 → 26.7.0 | FAILED | 4 | RED 1181 · harness 404 | #5 | … | 4 CVEs (CVE-2026-9796/9689/9798/11986 — admin/OIDC/CIBA/FGAP). RED on cc-ci harness regression (canonical install baseline 404 after nixpkgs bump), not the recipe — direct-deploy GREEN. Liquibase auto-migrates. |
| mailu | 2024.06.55 → 2024.06.57 | FAILED | 2 | RED 1191 · harness 404 | #6 | … | Roundcube webmail CVE-2026-54432/54433 (internet-facing) + redis 8.8.0 → 8.10.0-alpine. RED on same harness 404 regression as keycloak — dev-deploy GREEN. Upgrade stage skipped (install failed first). |
| lasuite-drive | redis 8.8.0 → 8.8.1 | GREEN | 1 | build 1187 ✓ | #6 | … | RedisBloom/TDigest RESTORE RCE fix (redis 8.8.1). App v0.20.0 unchanged. 8.10.0 minor skipped for sidecar cache. Ready to merge. |
| gitea | 1.27.0-rootless → 1.27.1-rootless | GREEN | 1 | build 1174 ✓ | #5 | … | Mandatory 2FA enforcement on OAuth2 authorize/grant endpoints (#38606) + ~32 bugfixes. Postgres held at 15.18. Patch-only. Ready to merge. |
| discourse | 2026.1.5 → 2026.7.1 | STALE | none | RED 1171 · stale test | #6 | … | 6-month ESR jump (2026.1 → 2026.7.1, a security intermediate) + redis 7.4 → 8.10-alpine. Unicorn → Pitchfork, Reactions on by default. RED on stale upgrade-tier base test (0.8→1.0 db-family break, unrelated to app bump) — recipe verified green locally. Re-run --with-tests. |
| bluesky-pds | 0.4.219 → 0.4.5009 | GREEN | none | build 1160 ✓ | #3 | … | PDS patch bump (Node 24 runtime, index.ts). caddy:2 unchanged. Extends last week's GREEN @0.4.5001. Ready to merge. |
| ghost | 6.45.0-alpine → 6.55.0-alpine | GREEN | none | build 1164 ✓ | #7 | … | 10 minor releases (markdown + llms.txt, automations SSO, spam protection, member labels). MySQL 8.4 unchanged. No breaking changes. Ready to merge. |
| hedgedoc | pg 16-alpine → 18-alpine | GREEN | none | build 1178 ✓ | #3 | … | pgautoupgrade in-place PG 16→18. App 1.11.1 unchanged. PGDATA pinned to /var/lib/postgresql/data (18-alpine changed its default). Auto-upgrades data on first start. |
| immich | v3.0.1 → v3.1.0 | GREEN | none | build 1180 ✓ | #4 | … | immich-server + ML v3.1.0, valkey:9 digest refreshed. Postgres combo unchanged (abra can't parse tag+digest pins — hand-edited). Ready to merge. |
| mattermost-lts | 11.7.8 → 11.9.0 | GREEN | none | build 1193 ✓ | #2 | … | ⚠️ 11.9.0 is an innovation release (EOL 2026-10-15), NOT ESR — recipe historically tracks ESR (11.7.x, supported through 2027-05-15). Operator decides. Postgres held at 15-alpine. |
| n8n | 2.32.4 → 2.33.3 | GREEN | none | build 1195 ✓ | #5 | … | n8n 2.33.3 (features + fixes). Postgres held at 18-alpine. mergeable=False (trivial image-line conflict, upstream at 2.27.2). Ready to merge after rebase. |
| cryptpad | — | UPTODATE | none | | | | Up-to-date (pinned version-2026.5.1 = newest upstream tag). |
| custom-html | — | UPTODATE | none | | | | Up-to-date. Summary claimed PR #5 (nginx 1.31.x) open, but live survey shows no open PRs — likely closed during reconcile. No newer bump. |
| mumble | — | UPTODATE | none | | #1 | … | Up-to-date. Stray ci/cfold-sweep probe PR #1 lingers — can be closed. |
| drone | — | SKIPPED | none | | | | Deployed 2.28.2 current; recipe pin 2.0.4 cross-major held for operator. |
| plausible | — | SKIPPED | none | | #5 | … | App v1.5.1→v2.0.0 cross-major held for operator. Live PR #5 title is 'revert: restore sleep 10' — not the cross-major upgrade the summary describes. |
Addendum
- ccci-bridge was broken all run — its mounted gitea-bot swarm secret (cc_ci_bridge_gitea_token_v1, dated 2026-05-31) is stale, returning HTTP 401 'user does not exist' on every !testme. The bridge silently dropped all triggers. All 15 verifications used a Drone-direct workaround (extract DRONE_TOKEN, mint a fresh scoped GITEA_TOKEN, trigger the build manually, reflect the verdict back). Operator fix: rotate both stale bridge swarm secrets to the sops values and roll the service — and consider making ensure_secret in bridge.nix re-sync swarm secrets to the sops source on reconcile so this doesn't recur.
- keycloak #5 and mailu #6 are RED on a cc-ci harness regression (canonical install baseline 404 after the 2026-08-03 nixpkgs bump), not recipe failures — both verified GREEN via direct dev-deploy. The harness regression needs investigating; it is blocking CI verification of two CVE-bearing security upgrades (4 CVEs on keycloak, 2 on mailu).
- discourse #6 is RED on a stale upgrade-tier base test (0.8.1+3.5.0 crosses the 0.8→1.0 db-family break, unrelated to the 2026.7.1 app bump). The recipe was verified green locally via direct dev-deploy. Re-run /recipe-upgrade discourse --with-tests to update the base test.
- custom-html-tiny carries two overlapping upgrade PRs: #10 (fresh sws-only, this run) and #9 (a prior run extended with the same static-web-server 2.44.0 bump on top of a git v2.54.0 bump). Both target sws 2.44.0 — decide which lands. PR #8 (regall sweep) also lingers.
- mattermost-lts 11.9.0 is an innovation release (EOL 2026-10-15), not an ESR. The recipe historically tracks the ESR line (11.7.x, supported through 2027-05-15). The operator explicitly targeted 11.9.0 this run, but the ESR/innovation mismatch is worth a deliberate decision — 11.9.0 ages out in ~10 weeks.
- plausible PR #5's live title ('revert: restore sleep 10 — needed for pgautoupgrade window') does not match the summary's description ('cross-major v1.5.1→v2.0.0 held for operator'). The cross-major upgrade is not in PR #5 — either it was never opened or the PR was repurposed. Worth checking what's actually queued for plausible.
- custom-html: the summary claims PR #5 (nginx 1.31.x) is open and awaiting merge, but the live survey shows no open PRs. The reconcile closed custom-html #6 (merged upstream); #5 may have been closed too. Worth verifying whether the nginx 1.31.x CVE fix has actually landed on the mirror.
- This run is a finish-run after two provider-side availability interruptions. The prior session completed 13 recipes before becoming unresumable; this fresh session finished the remaining 2 (mattermost-lts, n8n) + re-verified matrix-synapse (whose prior push was never verified at the new head). The interruptions don't affect the PRs but flag a reliability issue with managed-provider availability.
Security Bulletin
🔒 Critical CVE upgrades
Synapse v1.157.1 → v1.157.2 is a security release addressing 11 ELEMENTSEC advisories: 6 high (1071/1520/1717/1721/1729/1740), 3 moderate (1714/1718/1751), and 2 low (1703/1760). No breaking changes; synapse runs DB schema migrations on boot. Also bundles mautrix-telegram v0.2606.0 → v0.2607.0 (Alpine 3.24 base + rich-text parsing fixes). MAS 1.21.0 and nginx 1.31.3 were already in upstream main from a prior merged PR. All postgres DBs held at 13-alpine. !testme GREEN at build 1196.
The nginx 1.31.1/1.31.2 → 1.31.3 bump closes three CVEs (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434). It ships GREEN in
lasuite-docs (1.31.1→1.31.3, build 1185) and
lasuite-meet (1.31.2→1.31.3, build 1190). Both recipes also pick up the redis 8.8.1 RedisBloom/TDigest RESTORE RCE fix (see below). nginx serves here as a standard reverse proxy, so the bumps are drop-in.
redis 8.8.0 → 8.8.1 patches a crafted-RESTORE-payload flaw in RedisBloom and TDigest that can trigger out-of-bounds writes, potentially leading to RCE (RedisBloom issue #1044, released 2026-07-23).
lasuite-drive bumps redis only (build 1187 GREEN);
lasuite-meet picks up 8.8.1 alongside its nginx bump (build 1190);
lasuite-docs goes to 8.10.0, a stable minor that is a superset of the 8.8.x security patches. For sidecar caches the same-line 8.8.1 patch is the safe minimal change.
keycloak 26.6.4 → 26.7.0 carries four CVEs: CVE-2026-9796, CVE-2026-9689, CVE-2026-9798, CVE-2026-11986 (admin/OIDC/CIBA/FGAP). As an identity provider fronting other services,
keycloak is a high-priority merge. Liquibase auto-migrates the MariaDB on boot (back up the volume first). Twitter IDP implementation removed in 26.7.0 (legacy shim remains). Note: RED at build 1181 on the cc-ci harness 404 regression (not the recipe) — direct-deploy verified GREEN. Re-run once the harness is fixed.
mailu — Roundcube webmail CVE-2026-54432 / CVE-2026-54433 (high) · internet-facing
mailu 2024.06.55 → 2024.06.57 rolls up the Roundcube 1.6.17 security fixes CVE-2026-54432 and CVE-2026-54433 (webmail, internet-facing), plus redis 8.8.0 → 8.10.0-alpine. All 6
mailu images bumped together. RED at build 1191 on the same harness 404 regression as
keycloak — dev-deploy GREEN, but the upgrade stage was skipped (install failed first), so the image bump was never exercised by CI. Worth re-running once the harness is fixed to confirm the upgrade path.
static-web-server 2.43.0 → 2.44.0 delivers 4 security advisories (max Moderate) plus bug fixes and the v2 LTS move (v2 is now bug-fix + security only; v3 is the feature line). No breaking changes for this recipe. !testme GREEN at build 1162. Note: PR #10 is a fresh sws-only PR; PR #9 carries the same sws bump plus a git v2.54.0 bump — decide which lands.
gitea 1.27.1 — mandatory 2FA on OAuth2 endpoints (security hardening) ·
gitea gitea 1.27.0 → 1.27.1 enforces mandatory 2FA policy on OAuth2 authorize/grant endpoints (#38606), plus ~32 bugfixes (Actions reusable-workflow correctness, OIDC end-session after password login, repo deletion of seven more tables, ACME cert renewal, branch protection user list). No breaking changes; pure patch release. Postgres held at 15.18. !testme GREEN at build 1174.
What changed
synapse v1.157.1 → v1.157.2 — a security release addressing 11 ELEMENTSEC advisories (6 high, 3 moderate, 2 low). No breaking changes; DB schema migrations run on boot. Also bumps mautrix-telegram v0.2606.0 → v0.2607.0 (Alpine 3.24 base + rich-text parsing fixes). MAS 1.21.0 and nginx 1.31.3 were already in upstream main from a prior merged PR. All postgres DBs held at 13-alpine. Ready to merge.
impress v5.2.1 → v5.4.1 (four images: frontend/backend/celery/y-provider in lockstep) + redis 8.8.0 → 8.10.0 + nginx 1.31.1 → 1.31.3 (3 CVEs) + minio bump. v5.4.0 removed the default Bearer/JWT auth backend — API now accepts only the session cookie from the real OIDC authorization-code flow (security hardening; cc-ci tests already updated). AUTO_MIGRATIONS handles the DB. Clean GREEN.
meet v1.21.0 → v1.24.0 (frontend+backend+celery) + livekit v1.13.1 → v1.13.5 + redis 8.8.0 → 8.8.1 (RedisBloom/TDigest RCE fix) + nginx 1.31.2 → 1.31.3 (CVE batch). New features: PiP layout, recording admin search, SSO display-name enforcement, summary API v2 compat. The stale meeting-flow test was fixed and merged earlier today (cc-ci PR #13 — OIDC session login). Clean GREEN.
static-web-server 2.43.0 → 2.44.0 — 4 security advisories (max Moderate) + bug fixes + v2 LTS move. No breaking changes (recipe uses -d explicitly, doesn't touch --ignore-hidden-files, metrics, or pre-compressed files). Fresh sws-only PR #10; PR #9 carries the same sws bump plus a git v2.54.0 bump — operator decides which lands. PR #8 (regall sweep) also lingers.
26.6.4 → 26.7.0. Four CVEs (CVE-2026-9796/9689/9798/11986 — admin/OIDC/CIBA/FGAP). Liquibase auto-migrates on boot (back up MariaDB first). Twitter IDP implementation removed (legacy twitter-broker:v1 shim remains). RED at build 1181 on the cc-ci harness 404 regression (not the recipe) — direct-deploy GREEN. Re-run once the harness is fixed.
2024.06.55 → 2024.06.57 (all 6
mailu images: admin/antispam/nginx/imap/smtp/webmail) + redis 8.8.0 → 8.10.0-alpine. Roundcube 1.6.17 fixes CVE-2026-54432 and CVE-2026-54433 (webmail, internet-facing). RED at build 1191 on the harness 404 regression — dev-deploy GREEN, but the upgrade stage was skipped (install failed first), so the image bump was never exercised by CI. Re-run once the harness is fixed.
redis 8.8.0 → 8.8.1 only — the RedisBloom/TDigest RESTORE RCE fix. App v0.20.0 unchanged. The 8.10.0 minor (compact hashes, HIMPORT, TLS peer-cert) was deliberately skipped: for a sidecar cache the same-line security patch is the safe, minimal change. Clean GREEN.
1.27.0-rootless → 1.27.1-rootless. Enforces mandatory 2FA policy on OAuth2 authorize/grant endpoints (#38606) + ~32 bugfixes (Actions reusable-workflow correctness, OIDC end-session, repo deletion, ACME renewal, branch protection). No breaking changes; pure patch release. Postgres held at 15.18. Clean GREEN.
2026.1.5 → 2026.7.1 — a 6-month ESR jump to a security intermediate, plus redis 7.4-alpine → 8.10-alpine. Web server swapped Unicorn → Pitchfork (removed in 2026.4); Discourse Reactions enabled by default; rich_editor setting removed; .hbs/.js.es6 theme deprecations. RED on a stale upgrade-tier base test (0.8.1+3.5.0 crosses the 0.8→1.0 db-family break, unrelated to the app bump) — recipe verified green locally via direct dev-deploy. Re-run /recipe-upgrade
discourse --with-tests to update the base test.
0.4.219 → 0.4.5009 — PDS patch bump on the 0.4.x line (Node 24 runtime, /app/index.ts, @atproto/pds 0.5.1+). caddy:2 unchanged (no newer evaluated tag). Extends last week's GREEN @0.4.5001. No env/config changes. Clean GREEN.
6.45.0-alpine → 6.55.0-alpine — 10 minor releases: markdown + llms.txt support, automations SSO adapter hooks, publisher gift links, configurable admin session max-age, social-web handle prefs, tax-ID collection, member labels/avatars/custom fields, spam-signup protection, secure filename generation. No breaking changes, no required DB migration (Ghost auto-migrates on boot). MySQL 8.4 unchanged. Clean GREEN.
pgautoupgrade 16-alpine → 18-alpine — an in-place Postgres major 16→18 upgrade handled by pgautoupgrade on first start. App (quay.io/
hedgedoc/
hedgedoc) stays at 1.11.1 (up-to-date). Key gotcha: 18-alpine changed its default PGDATA from /var/lib/postgresql/data to /var/lib/postgresql/18/docker — the PR pins PGDATA=/var/lib/postgresql/data so pgautoupgrade detects the existing 16 data and runs pg_upgrade in place (without the pin, data would be lost). Clean GREEN.
immich-server + immich-machine-learning v3.0.1 → v3.1.0, valkey:9 digest refreshed. Postgres combo unchanged (abra can't parse tag-plus-digest image pins like postgres:14-vectorchord0.4.3-pgvectors0.3.0@sha256:… — all tags hand-edited, a known tooling gap). Extends last week's GREEN @v3.1.0. Clean GREEN.
11.7.8 → 11.9.0. ⚠️ 11.9.0 is an innovation release (EOL 2026-10-15), NOT an ESR — the
mattermost-lts recipe historically tracks the ESR line (11.7.x, supported through 2027-05-15; current ESR latest is 11.7.8 released 2026-07-31). The operator explicitly targeted 11.9.0 this run; the ESR/innovation mismatch is worth a deliberate decision. Postgres held at 15-alpine (16 broke PGDATA). Reconcile with fix PR #1 (backup restore no-op fix). Clean GREEN.
2.32.4 → 2.33.3 — features + fixes across the 2.33.x line. Postgres held at 18-alpine. mergeable=False: a trivial image-line conflict with upstream main (which is at 2.27.2) — needs a rebase before merge. Clean GREEN.