A finish-run with a sharp edge: fourteen of seventeen surveyed recipes are !testme GREEN and merge-ready, two are up-to-date, and only plausible's long-standing cross-major hold is RED — but the headline is gitea. The 1.27.0→1.27.1 patch re-verified GREEN (build 1207) and the advisory scan confirms it fixes TWO CRITICAL (CVSS 9.8) RCEs (CVE-2026-59774, CVE-2026-60004), yet its upgrade PR #5 was closed unmerged on 2026-08-10 — re-issue that bump first. Then merge discourse #6 — now a determinate 140 CVEs once its redis 7.4→8.10 sidecar is counted, including the CRITICAL CVE-2025-49844 — followed by keycloak #6 (seven CVEs, five high) and mailu #6 (two internet-facing Roundcube webmail CVEs); plausible's critical CVE-2026-8467 is blocked behind its RED v3 upgrade, pending the operator's TOTP_VAULT_KEY and release.
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|---|---|---|---|---|---|---|
| gitea | 1.27.0-rootless → 1.27.1-rootless | GREEN | 2 | build 1207 ✓ | #5 | … | Two CRITICAL (CVSS 9.8) RCEs fixed in 1.27.1 — CVE-2026-59774 (GHSA-6v53-hr58-556r), CVE-2026-60004 (GHSA-rcr6-4jqh-j84m); plus oauth2 mandatory-2FA, repo-deletion cleanup, webhook/ACME fixes; postgres 15.18 HELD. ⚠ PR #5 was CLOSED UNMERGED on 2026-08-10 — the two RCEs are NOT landed. Re-issue the bump. Fix PRs #6 (GREEN) and #4 (pending) are open but neither bumps gitea. |
| plausible | v2.0.0 → v3.2.1 (cross-major, Docker Hub → ghcr.io) | FAILED | 1 | RED 1224 · app-health | #5 | … | Critical CVE-2026-8467 (GHSA-mhcv-h7gf-57cf) is fixed in v3.2.1, but the PR is RED: test_plausible_root_serves health-check doesn't converge in 60s (GET /api/health → 200 but not healthy). Install/upgrade/backup/restore all pass. Operator decision: TOTP_VAULT_KEY required for CE v3.x, then `abra recipe release plausible -x`. Open since June. |
| discourse | 3.5.3 → 2026.7.1 (ESR) · redis 7.4 → 8.10-alpine | GREEN | 140 | build 1235 ✓ | #6 | … | ESR jump (semver 3.5.3 → calver 2026.7.1); redis 7.4-alpine → 8.10-alpine; pg18 unchanged. 140 CVEs fixed = 123 discourse (incl. first-party plugin advisories, dated across the ESR window 2025-12-30 → 2026-07-31) + 17 redis, among them CVE-2025-49844 (CRITICAL). Twelve of the redis seventeen publish no fix version and were resolved from the release notes naming them. Re-verified GREEN (#1206 then #1235). |
| keycloak | 26.7.0 → 26.7.1 | GREEN | 7 | build 1213 ✓ | #6 | … | Seven CVEs fixed in 26.7.1 (5 high, 2 medium, all GHSA-backed): CVE-2026-15572/15573/16102/16442/16443 (high), 16071/16100 (medium). Release notes also call out a JWE requestObjectSignatureAlg bypass, hardcoded role-mapper injection, and three FGAP v2 bypasses. mariadb 12.3 unchanged. Patch — no config changes. Prior #5 merged upstream as 10.9.0+26.7.0 (auto-closed). |
| mailu | 2024.06.55 → 2024.06.57 · redis 8.8.0 → 8.10.0-alpine | GREEN | 2 | build 1217 ✓ | #6 | … | Roundcube webmail CVE-2026-54432 + CVE-2026-54433 (fixed in 2024.06.56, roundcube 1.6.17) + autoconfig fix (2024.06.57). Internet-facing — prioritise. redis 8.10.0-alpine (cache-only); certdumper v2.11.4 unchanged. No config changes. Reconcile with backup-labels PR #3. |
| mattermost-lts | 11.9.0 → 11.10.0 | GREEN | none | build 1223 ✓ | #2 | … | ⚠ 11.10.0 is a GitHub-marked PRE-RELEASE on the innovation line (EOL ~2026-11-15); real ESR = 11.7.8 (EOL 2027-05-15). Operator decides innovation vs ESR. postgres 15-alpine HELD. A first fast-forward lost the restore fix → #1220/#1221 RED, re-based → #1223 GREEN. Reconcile with restore-fix PR #1 (now folded into #2). |
| n8n | 2.33.3 → 2.34.2 | GREEN | none | build 1234 ✓ | #5 | … | ⚠ 2.34.2 is GitHub-marked Pre-release (2.33.5 holds the Latest badge); operator-directed. 2.34.0 deprecates the workflow activate/deactivate public API endpoints. postgres 18-alpine HELD. No required migrations. |
| immich | v3.0.1 → v3.1.0 | GREEN | none | build 1211 ✓ | #4 | … | immich-server + immich-machine-learning v3.0.1 → v3.1.0; postgres combo unchanged. Upstream recipe main published 1.10.0+v3.1.0 independently; PR #4 carries divergent pins (pgvectors0.3.0 vs upstream 0.2.0; valkey 8e8d64b4 vs 3acc0687) — operator decides merge vs close-as-superseded. #1210 hit a transient gitea 401, retried GREEN #1211. |
| lasuite-meet | v1.24.0 → v1.25.2 | GREEN | none | build 1215 ✓ | #8 | … | meet frontend+backend+celery v1.24.0 → v1.25.2 (matched set). livekit v1.13.5 / redis 8.10.0 / nginx 1.31.3 unchanged. v1.25.0 upgraded the frontend livekit-client JS, not livekit-server. |
| matrix-synapse | synapse v1.157.2 → v1.158.0 · mas 1.21.0 → 1.22.0 | GREEN | none | build 1218 ✓ | #5 | … | synapse v1.158.0 + mas 1.22.0; both auto-migrate on boot. postgres 13-alpine HELD (multiple dbs — PG13 EOL Nov 2025; operator to plan a dump/restore). No CVEs classified by the scan. |
| ghost | 6.55.0-alpine → 6.56.0-alpine | GREEN | none | build 1208 ✓ | #7 | … | ghost 6.55.0 → 6.56.0-alpine; mysql 8.4 HELD. Subagent died mid step-2b (leaked dev-ghost torn down by orchestrator); bump + PR extension completed directly. Reconcile with old regall-sweep PR #6. |
| hedgedoc | pgautoupgrade 16-alpine → 18-alpine (app 1.11.1 unchanged) | GREEN | none | build 1209 ✓ | #3 | … | In-place postgres major 16 → 18 via pgautoupgrade (PGDATA=/var/lib/postgresql/data pin required — 18-alpine moved the default). App 1.11.1 unchanged. cc-ci tests use sqlite, so the db major bump is outside CI coverage. Old generic-suite probe PR #1 lingers. |
| bluesky-pds | 0.4.219 → 0.4.5009 | GREEN | none | build 1205 ✓ | #3 | … | bluesky-social/pds 0.4.219 → 0.4.5009; caddy:2 unchanged. Re-verified (head byte-identical to 2026-08-03 GREEN). Subagent died mid step-2b (secp256k1 PLC key), leaked dev deploy torn down. Routing-rename fix PR #4 (pending) open alongside. |
| lasuite-drive | redis 8.8.1 → 8.10.0 · collabora 25.04.9.4.1 → 25.04.10.3.1 | GREEN | none | build 1216 ✓ | #6 | … | redis 8.8.1 → 8.10.0 + collabora 25.04.9.4.1 → 25.04.10.3.1; minio + onlyoffice up-to-date (minio's newer releases moved to AIStor/quay.io — flagged). 26.04.x collabora deliberately avoided (crashes in-deploy). Old regall-sweep PR #3 lingers. |
| lasuite-docs | redis → 8.10.0 · nginx → 1.31.3 (impress v5.4.1) | GREEN | none | build 1214 ✓ | #7 | … | impress already v5.4.1 (latest); PR #7 bumps redis → 8.10.0 + nginx → 1.31.3. #1212 was a transient gitea connection-refused blip (4s), retried GREEN #1214. |
| custom-html-tiny | → static-web-server 2.44.0 (carry-over) | GREEN | none | build 1162 ✓ | #10 | … | Carry-over from 2026-08-03 (sws 2.44.0, GREEN #1162); not re-verified this run (no per-recipe log). Two old regall/tooling PRs (#9, #8) open alongside. |
| cryptpad | — | UPTODATE | none | Up-to-date (pinned version-2026.5.1 = newest upstream; nginx 1.31 up-to-date). No open PR. | |||
| custom-html | — | UPTODATE | none | Up-to-date. Last week's nginx 1.31.3 + alpine/git v2.54.0 PR #5 merged upstream as 1.13.2+1.31.3 and auto-closed by reconcile. No PR to action. | |||
| drone | — | UPTODATE | none | Deployed 2.28.2 current; recipe pin held cross-major. 0 open PRs. (No per-recipe log this run.) | |||
| mumble | — | UPTODATE | none | #1 | … | Up-to-date (mumble-server v1.6.870-0, mumble-web 0.5). Stray CI-tooling PR #1 lingers — can be closed. | |
| wordpress | — | UPTODATE | none | Newly enrolled 2026-08-04 (cc-ci PR #14 merged). 0 open PRs; not reached before the run's interruption. |
Addendum