Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of August 7, 2026report.ci.commoninternet.net2026-08-11 01:29 UTC

A finish-run with a sharp edge: fourteen of seventeen surveyed recipes are !testme GREEN and merge-ready, two are up-to-date, and only plausible's long-standing cross-major hold is RED — but the headline is gitea. The 1.27.0→1.27.1 patch re-verified GREEN (build 1207) and the advisory scan confirms it fixes TWO CRITICAL (CVSS 9.8) RCEs (CVE-2026-59774, CVE-2026-60004), yet its upgrade PR #5 was closed unmerged on 2026-08-10 — re-issue that bump first. Then merge discourse #6 — now a determinate 140 CVEs once its redis 7.4→8.10 sidecar is counted, including the CRITICAL CVE-2025-49844 — followed by keycloak #6 (seven CVEs, five high) and mailu #6 (two internet-facing Roundcube webmail CVEs); plausible's critical CVE-2026-8467 is blocked behind its RED v3 upgrade, pending the operator's TOTP_VAULT_KEY and release.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
gitea1.27.0-rootless → 1.27.1-rootlessGREEN2build 1207 ✓#5Two CRITICAL (CVSS 9.8) RCEs fixed in 1.27.1 — CVE-2026-59774 (GHSA-6v53-hr58-556r), CVE-2026-60004 (GHSA-rcr6-4jqh-j84m); plus oauth2 mandatory-2FA, repo-deletion cleanup, webhook/ACME fixes; postgres 15.18 HELD. ⚠ PR #5 was CLOSED UNMERGED on 2026-08-10 — the two RCEs are NOT landed. Re-issue the bump. Fix PRs #6 (GREEN) and #4 (pending) are open but neither bumps gitea.
plausiblev2.0.0 → v3.2.1 (cross-major, Docker Hub → ghcr.io)FAILED1RED 1224 · app-health#5Critical CVE-2026-8467 (GHSA-mhcv-h7gf-57cf) is fixed in v3.2.1, but the PR is RED: test_plausible_root_serves health-check doesn't converge in 60s (GET /api/health → 200 but not healthy). Install/upgrade/backup/restore all pass. Operator decision: TOTP_VAULT_KEY required for CE v3.x, then `abra recipe release plausible -x`. Open since June.
discourse3.5.3 → 2026.7.1 (ESR) · redis 7.4 → 8.10-alpineGREEN140build 1235 ✓#6ESR jump (semver 3.5.3 → calver 2026.7.1); redis 7.4-alpine → 8.10-alpine; pg18 unchanged. 140 CVEs fixed = 123 discourse (incl. first-party plugin advisories, dated across the ESR window 2025-12-30 → 2026-07-31) + 17 redis, among them CVE-2025-49844 (CRITICAL). Twelve of the redis seventeen publish no fix version and were resolved from the release notes naming them. Re-verified GREEN (#1206 then #1235).
keycloak26.7.0 → 26.7.1GREEN7build 1213 ✓#6Seven CVEs fixed in 26.7.1 (5 high, 2 medium, all GHSA-backed): CVE-2026-15572/15573/16102/16442/16443 (high), 16071/16100 (medium). Release notes also call out a JWE requestObjectSignatureAlg bypass, hardcoded role-mapper injection, and three FGAP v2 bypasses. mariadb 12.3 unchanged. Patch — no config changes. Prior #5 merged upstream as 10.9.0+26.7.0 (auto-closed).
mailu2024.06.55 → 2024.06.57 · redis 8.8.0 → 8.10.0-alpineGREEN2build 1217 ✓#6Roundcube webmail CVE-2026-54432 + CVE-2026-54433 (fixed in 2024.06.56, roundcube 1.6.17) + autoconfig fix (2024.06.57). Internet-facing — prioritise. redis 8.10.0-alpine (cache-only); certdumper v2.11.4 unchanged. No config changes. Reconcile with backup-labels PR #3.
mattermost-lts11.9.0 → 11.10.0GREENnonebuild 1223 ✓#2⚠ 11.10.0 is a GitHub-marked PRE-RELEASE on the innovation line (EOL ~2026-11-15); real ESR = 11.7.8 (EOL 2027-05-15). Operator decides innovation vs ESR. postgres 15-alpine HELD. A first fast-forward lost the restore fix → #1220/#1221 RED, re-based → #1223 GREEN. Reconcile with restore-fix PR #1 (now folded into #2).
n8n2.33.3 → 2.34.2GREENnonebuild 1234 ✓#5⚠ 2.34.2 is GitHub-marked Pre-release (2.33.5 holds the Latest badge); operator-directed. 2.34.0 deprecates the workflow activate/deactivate public API endpoints. postgres 18-alpine HELD. No required migrations.
immichv3.0.1 → v3.1.0GREENnonebuild 1211 ✓#4immich-server + immich-machine-learning v3.0.1 → v3.1.0; postgres combo unchanged. Upstream recipe main published 1.10.0+v3.1.0 independently; PR #4 carries divergent pins (pgvectors0.3.0 vs upstream 0.2.0; valkey 8e8d64b4 vs 3acc0687) — operator decides merge vs close-as-superseded. #1210 hit a transient gitea 401, retried GREEN #1211.
lasuite-meetv1.24.0 → v1.25.2GREENnonebuild 1215 ✓#8meet frontend+backend+celery v1.24.0 → v1.25.2 (matched set). livekit v1.13.5 / redis 8.10.0 / nginx 1.31.3 unchanged. v1.25.0 upgraded the frontend livekit-client JS, not livekit-server.
matrix-synapsesynapse v1.157.2 → v1.158.0 · mas 1.21.0 → 1.22.0GREENnonebuild 1218 ✓#5synapse v1.158.0 + mas 1.22.0; both auto-migrate on boot. postgres 13-alpine HELD (multiple dbs — PG13 EOL Nov 2025; operator to plan a dump/restore). No CVEs classified by the scan.
ghost6.55.0-alpine → 6.56.0-alpineGREENnonebuild 1208 ✓#7ghost 6.55.0 → 6.56.0-alpine; mysql 8.4 HELD. Subagent died mid step-2b (leaked dev-ghost torn down by orchestrator); bump + PR extension completed directly. Reconcile with old regall-sweep PR #6.
hedgedocpgautoupgrade 16-alpine → 18-alpine (app 1.11.1 unchanged)GREENnonebuild 1209 ✓#3In-place postgres major 16 → 18 via pgautoupgrade (PGDATA=/var/lib/postgresql/data pin required — 18-alpine moved the default). App 1.11.1 unchanged. cc-ci tests use sqlite, so the db major bump is outside CI coverage. Old generic-suite probe PR #1 lingers.
bluesky-pds0.4.219 → 0.4.5009GREENnonebuild 1205 ✓#3bluesky-social/pds 0.4.219 → 0.4.5009; caddy:2 unchanged. Re-verified (head byte-identical to 2026-08-03 GREEN). Subagent died mid step-2b (secp256k1 PLC key), leaked dev deploy torn down. Routing-rename fix PR #4 (pending) open alongside.
lasuite-driveredis 8.8.1 → 8.10.0 · collabora 25.04.9.4.1 → 25.04.10.3.1GREENnonebuild 1216 ✓#6redis 8.8.1 → 8.10.0 + collabora 25.04.9.4.1 → 25.04.10.3.1; minio + onlyoffice up-to-date (minio's newer releases moved to AIStor/quay.io — flagged). 26.04.x collabora deliberately avoided (crashes in-deploy). Old regall-sweep PR #3 lingers.
lasuite-docsredis → 8.10.0 · nginx → 1.31.3 (impress v5.4.1)GREENnonebuild 1214 ✓#7impress already v5.4.1 (latest); PR #7 bumps redis → 8.10.0 + nginx → 1.31.3. #1212 was a transient gitea connection-refused blip (4s), retried GREEN #1214.
custom-html-tiny→ static-web-server 2.44.0 (carry-over)GREENnonebuild 1162 ✓#10Carry-over from 2026-08-03 (sws 2.44.0, GREEN #1162); not re-verified this run (no per-recipe log). Two old regall/tooling PRs (#9, #8) open alongside.
cryptpadUPTODATEnoneUp-to-date (pinned version-2026.5.1 = newest upstream; nginx 1.31 up-to-date). No open PR.
custom-htmlUPTODATEnoneUp-to-date. Last week's nginx 1.31.3 + alpine/git v2.54.0 PR #5 merged upstream as 1.13.2+1.31.3 and auto-closed by reconcile. No PR to action.
droneUPTODATEnoneDeployed 2.28.2 current; recipe pin held cross-major. 0 open PRs. (No per-recipe log this run.)
mumbleUPTODATEnone#1Up-to-date (mumble-server v1.6.870-0, mumble-web 0.5). Stray CI-tooling PR #1 lingers — can be closed.
wordpressUPTODATEnoneNewly enrolled 2026-08-04 (cc-ci PR #14 merged). 0 open PRs; not reached before the run's interruption.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

gitea 1.27.1 — TWO critical (CVSS 9.8) RCEs (CVE-2026-59774, CVE-2026-60004) · PR CLOSED UNMERGED
The 1.27.0→1.27.1 patch fixes two critical remote-code-execution flaws — CVE-2026-59774 (GHSA-6v53-hr58-556r) and CVE-2026-60004 (GHSA-rcr6-4jqh-j84m), both fixed in 1.27.1 — alongside oauth2 mandatory-2FA enforcement, repo-deletion cleanup across seven tables, and webhook/ACME fixes. gitea is an internet-facing git forge, so RCE is severe. This run re-verified PR #5 GREEN (build 1207), but #5 was CLOSED UNMERGED on 2026-08-10: the two RCEs are NOT yet landed in the recipe. The two open fix PRs (#6 APP_INI_VERSION, #4 app.ini volume) do not bump gitea. Re-issue the 1.27.1 bump and merge it first. (This is the same pair misreported as 'none' on 2026-08-07; the advisory scan now confirms them.)
plausible v3.2.1 — critical CVE-2026-8467 · blocked behind RED v3 upgrade
plausible/analytics CVE-2026-8467 (GHSA-mhcv-h7gf-57cf, critical, fixed in v3.2.1) is fixed by the target of PR #5 — but #5 is RED (#1224): the app health check (test_plausible_root_serves) doesn't converge in 60s though GET /api/health returns 200. Install/upgrade/backup/restore all pass (level 3/5). The block is the community-edition v3 migration: TOTP_VAULT_KEY is required for CE v3.x, then `abra recipe release plausible -x`. Open since June; the only RED recipe this run. The critical CVE stays unpatched until the v3 upgrade lands.
discourse — redis CVE-2025-49844 (critical) + CVE-2024-31449 / CVE-2025-62507 (high)
The discourse ESR PR also moves redis 7.4-alpine → 8.10-alpine, which closes seventeen redis advisories — headed by CVE-2025-49844 (GHSA-4789-qfc9-5f9q, CRITICAL; patched 7.4.6/8.0.4/8.2.2) and two high-severity Lua-engine RCEs, CVE-2024-31449 (patched 7.4.1) and CVE-2025-62507 (patched 8.2.3). The pinned 7.4 predates every one of them. Twelve of the seventeen publish no fix version at all and were confirmed from the redis release notes that name them. discourse's own 123 advisories over the same window are mostly medium and largely first-party plugins; the redis critical is the reason to merge promptly. redis is not published on this recipe, but it is reachable from the app container.
keycloak 26.7.1 — seven CVEs (5 high, 2 medium) on the identity provider · GREEN
keycloak 26.7.0→26.7.1 is a security patch fixing seven GHSA-backed advisories the scan classifies as fixed in 26.7.1: CVE-2026-15572/15573/16102/16442/16443 (high) and CVE-2026-16071/16100 (medium). The release notes also call out a JWE requestObjectSignatureAlg enforcement bypass, a hardcoded role-mapper injection in manage-clients, and three Fine-Grained Admin Permissions (FGAP v2) bypasses. As an identity provider fronting other services, keycloak is high-priority. mariadb 12.3 unchanged; no config changes. !testme GREEN at build 1213. Prior #5 merged upstream as 10.9.0+26.7.0 (auto-closed); #6 is fresh.
mailu — Roundcube webmail CVE-2026-54432/54433 (high) · internet-facing
mailu 2024.06.55→2024.06.57 rolls up the Roundcube 1.6.17 security fixes CVE-2026-54432 and CVE-2026-54433 (shipped in 2024.06.56) plus a k9-mail autoconfig fix (2024.06.57) and redis 8.8.0→8.10.0-alpine (cache-only). The deterministic scan saw the two Roundcube CVEs but couldn't version-classify the sidecar image; the release notes confirm them, so the count is the union: 2. Webmail is exposed on a mail host — prioritise. No config changes; !testme GREEN at build 1217. Reconcile with backup-labels PR #3.

What changed

1.27.0-rootless → 1.27.1-rootless. A security patch fixing two critical (CVSS 9.8) RCEs (CVE-2026-59774, CVE-2026-60004) plus oauth2 mandatory-2FA, repo-deletion cleanup, and webhook/ACME fixes; postgres 15.18 HELD (major DB bump is operator-guided). No breaking changes. ⚠ PR #5 was closed UNMERGED on 2026-08-10 — the RCEs are not landed; re-issue the bump. Fix PRs #6 (APP_INI_VERSION v23) and #4 (app.ini volume) are open but neither bumps gitea.
app v2.0.0 → v3.2.1 (cross-major; registry move Docker Hub → ghcr.io/plausible/community-edition) + clickhouse 23.4.2.11-alpine → 24.12-alpine (the pairing Plausible ships with v3.2.1) + config-version bumps. RED at #1224: the app health check doesn't converge in 60s though /api/health returns 200; install/upgrade/backup/restore all pass. Operator must set TOTP_VAULT_KEY for CE v3.x and run `abra recipe release plausible -x`. Open since June.
26.7.0 → 26.7.1. Security patch: seven GHSA-backed CVEs fixed in 26.7.1 (5 high — CVE-2026-15572/15573/16102/16442/16443; 2 medium — 16071/16100), with release-note calls-outs for a JWE requestObject bypass, role-mapper injection, and three FGAP v2 bypasses. mariadb 12.3 unchanged; no config changes; DB auto-migrates. Prior #5 merged upstream as 10.9.0+26.7.0 (auto-closed); #6 is fresh.
2024.06.55 → 2024.06.57 across all mailu images, redis 8.8.0-alpine → 8.10.0-alpine. 2024.06.56 ships Roundcube 1.6.17 fixing CVE-2026-54432 + CVE-2026-54433 (internet-facing webmail); 2024.06.57 fixes k9-mail autoconfig. certdumper v2.11.4 unchanged. No migrations/config changes. Reconcile with backup-labels PR #3.
3.5.3 → 2026.7.1 (ESR; semver → calver), redis 7.4-alpine → 8.10-alpine, pg18 unchanged. Fixes 140 CVEs: 123 on discourse itself — counted by advisory publish date across the ESR window (2025-12-30 → 2026-07-31), since versions are unorderable across the scheme change, and inflated by discourse filing first-party PLUGIN advisories on the same repo — plus 17 on redis, judged by its own 7.4 → 8.10 window. Re-verified GREEN (#1206 then #1235). Reconcile with side-PRs #8/#5/#1 noted in prior runs.
11.9.0 → 11.10.0 on the innovation line. ⚠ 11.10.0 is a GitHub-marked PRE-RELEASE; the real ESR is 11.7.8 (EOL 2027-05-15) — operator decides. postgres 15-alpine HELD. A first fast-forward based on upstream main lost the pg_backup.sh restore hook → #1220/#1221 RED; re-based on the PR tip → #1223 GREEN (restore test failures=0). Reconcile with restore-fix PR #1 (folded into #2).
2.33.3 → 2.34.2. ⚠ 2.34.2 is GitHub-marked Pre-release (2.33.5 holds the Latest badge); operator-directed. 2.34.0 deprecates the workflow activate/deactivate public API endpoints. postgres 18-alpine HELD; no required migrations.
immich-server + immich-machine-learning v3.0.1 → v3.1.0; postgres combo unchanged. Upstream recipe main independently published 1.10.0+v3.1.0; PR #4 carries divergent pins (pgvectors0.3.0 vs upstream 0.2.0; valkey 8e8d64b4 vs 3acc0687) — operator decides merge vs close-as-superseded. #1210 hit a transient gitea 401, retried GREEN #1211.
meet frontend+backend+celery v1.24.0 → v1.25.2 (matched set). livekit v1.13.5 / redis 8.10.0 / nginx 1.31.3 unchanged. v1.25.0 upgraded the frontend livekit-client JS, not livekit-server.
synapse v1.157.2 → v1.158.0 + mas 1.21.0 → 1.22.0; both auto-migrate on boot. postgres 13-alpine HELD across multiple dbs (PG13 EOL Nov 2025 — operator to plan a dump/restore). No CVEs classified by the scan.
6.55.0-alpine → 6.56.0-alpine; mysql 8.4 HELD. Subagent died mid step-2b (a leaked dev-ghost stack); the orchestrator tore it down and completed the bump + PR #7 extension + re-verification directly.
pgautoupgrade 16-alpine → 18-alpine (in-place major upgrade handled by pgautoupgrade itself); app 1.11.1 unchanged. Requires the PGDATA=/var/lib/postgresql/data pin — 18-alpine moved the default. cc-ci tests use sqlite, so the db major bump is outside CI coverage.
bluesky-social/pds 0.4.219 → 0.4.5009; caddy:2 unchanged. Re-verified — head byte-identical to the 2026-08-03 GREEN. Subagent died mid step-2b (secp256k1 PLC rotation key); leaked dev deploy torn down by the orchestrator, re-verified directly. Routing-rename fix PR #4 (pending) open alongside.
redis 8.8.1 → 8.10.0 + collabora 25.04.9.4.1 → 25.04.10.3.1; minio + onlyoffice up-to-date (minio's newer releases moved to AIStor/quay.io — flagged for operator). 26.04.x collabora deliberately avoided (crashes in-deploy).
impress already v5.4.1 (latest); PR #7 bumps redis → 8.10.0 + nginx → 1.31.3. #1212 was a transient gitea connection-refused blip (4s CI failure), retried GREEN #1214.
Carry-over from 2026-08-03: static-web-server 2.44.0, GREEN at #1162. Not re-verified this run (no per-recipe log) — worth a re-test before merge. Two old regall/tooling PRs (#9, #8) open alongside.