Co-op Cloud Recipe CI · Weekly Edition
The Recipe Report
Week of August 15, 2026report.ci.commoninternet.net2026-08-15 20:37 UTC
A clean run — six upgrades GREEN, none failed, three skipped as up-to-date — but the urgency this week is the backlog: gitea #7 (open since last week) now resolves seven CVEs including five high-severity ones on a likely internet-facing git server, and bluesky-pds #3 carries two high Node.js CVEs from its base-image bump. Address those two first, then the six routine GREEN bumps from this run (mattermost's 10→11 LTS jump bundles eleven medium CVEs and a backup-restore fix; lasuite-drive, lasuite-meet, mailu, matrix-synapse, n8n are straightforward). Three recipes were skipped as up-to-date.
The full wire — every recipe, in priority order
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|
| gitea | 1.27.1-rootless → 1.27.2-rootless + pg 15.18→15.19 | GREEN | 7 | build 1263 ✓ | #7 | … | Seven CVEs (5 HIGH: CVE-2026-73278/73535/73539/73800/73804, 2 medium). Scan found 0 on 08-14, 7 on re-scan today — GHSA DBs lagged. PG 15.19 also fixes 20+ (unclassified — floor). Also open: fix PR #4 (app.ini config volume, GREEN #1250). Prior run; merge first. |
| bluesky-pds | 0.4.219 → 0.4.5027 | GREEN | 5 | build 1260 ✓ | #3 | … | Five Node.js CVEs via Node 20→24 base image: 2 HIGH (CVE-2026-48618 TLS auth bypass, CVE-2026-48933 WebCrypto overflow) + 3 MEDIUM. CI needed 3 runs (2 infra flakes). Also open: fix PR #4 (routing rename, CI pending). Prior run; merge first. |
| mattermost-lts | 10.11.22 → 11.10.0 | GREEN | 11 | build 1277 ✓ | #2 | … | Eleven CVEs (all medium/low, NVD patched-version ranges). Major LTS jump 10→11 — operator review before merge. Bundles pg_backup restore fix (prior restore was a no-op). PG held at 15. Fix PR #1 folded into #2. This run. |
| ghost | 6.45.0-alpine → 6.57.1-alpine | GREEN | 9 | build 1261 ✓ | #7 | … | Nine CVEs (all medium, fixed by v6.54.1: CVE-2026-70588–70596). MySQL stays at 8.4 (Ghost doesn't support 9.x). No breaking changes. CI needed 3 runs (2 drone-runner flakes). Prior run. |
| hedgedoc | pgautoupgrade 16 → 17 (app unchanged) | FAILED | none | RED 1266 · clone | #3 | … | Sidecar PG bump only (app stays 1.11.1). CI RED — clone exit 128, drone-runner-exec infra issue, not a recipe regression. cc-ci tests use SQLite; PG bump not exercised. Merge after infra recovers. |
| lasuite-drive | v0.19.0 → v0.21.0 | GREEN | none | build 1267 ✓ | #6 | … | Also redis 8.8→8.10, nginx 1.31.2→1.31.3, collabora 25.04.9.4.1→25.04.10.3.1, onlyoffice 9.3.1.2→9.4.1.2. Zero CVEs (scan: 24 sources, clean). PR #6 extended. This run. |
| lasuite-meet | v1.25.2 → v1.27.0 | GREEN | none | build 1272 ✓ | #9 | … | Zero CVEs (scan: 15 sources, clean). Run verified GREEN #1272 on v1.27.0, but live CI now RED #1273 on a different head (v1.26.0 title) — re-verify before merge. See Addendum. |
| mailu | 2024.06.57 → 2024.06.58 | GREEN | none | build 1274 ✓ | #7 | … | All 6 services (nginx, admin, dovecot, postfix, rspamd, webmail). Zero CVEs identified (47 sidecar advisories unclassified — floor). Also open: feat PR #3 (backupbot labels, old GREEN #483). This run. |
| matrix-synapse | v1.157.1 → v1.158.0 | GREEN | none | build 1276 ✓ | #5 | … | Also MAS 1.21→1.22, mautrix-telegram v0.2606→v0.2607. Zero CVEs (scan: 24 sources, clean). Bridge DBs held at pg 13-alpine (multi-major too risky). PR #5 rebased clean. This run. |
| n8n | 2.34.4 → 2.35.3 | GREEN | none | build 1278 ✓ | #7 | … | Single-service patch bump within 2.x; postgres unchanged at 18. Zero CVEs (scan: 9 sources, clean). This run. |
| custom-html-tiny | 2.43.0 → 2.44.0 | GREEN | none | build 1159 ✓ | #9 | … | static-web-server 2.44: 4 security advisories (Moderate/Low GHSAs, no CVE IDs — scan counts 0). v2 is now LTS. Bridge-bypass (stale Gitea token). Prior run. |
| lasuite-docs | v5.2.1 → v5.4.1 | GREEN | none | build 1214 ✓ | #7 | … | Also redis 8.8→8.10, nginx 1.31.1→1.31.3, minio 2025-05-24→2025-09-07. Zero CVEs (scan: 18 sources, clean). Recipe now up-to-date; PR #7 re-verified. Prior run. |
| immich | — | UPTODATE | none | build 1211 ✓ | #4 | … | Up-to-date at v3.1.0 (all images at latest per immich's official pin matrix). PR #4 is superseded — upstream main already carries v3.1.0. Can be closed. |
| plausible | — | SKIPPED | none | build 1253 ✓ | #5 | … | Skipped — dirty worktree (abra.sh CLICKHOUSE_USER_CONF_VERSION v2→v3) + app up-to-date (v2.0.0). PR #5 is a revert (restore sleep 10), not an upgrade. |
| mumble | — | UPTODATE | none | | | | Up-to-date (mumble-server v1.6.870-0, mumble-web 0.5). No PR. |
| wordpress | — | UPTODATE | none | | | | Up-to-date (wordpress 7.0.4, mariadb 12.3). No PR. |
| cryptpad | — | UPTODATE | none | | | | Up-to-date. No open PR. Not surveyed this run. |
| custom-html | — | UPTODATE | none | | | | Up-to-date. No open PR. Not surveyed this run. |
| discourse | — | UPTODATE | none | | | | Up-to-date. No open PR. Not surveyed this run. |
| drone | — | UPTODATE | none | | | | Up-to-date. No open PR. Not surveyed this run. |
| keycloak | — | UPTODATE | none | | | | Up-to-date. No open PR. Not surveyed this run. |
| libredesk | — | UPTODATE | none | | | | Up-to-date. No open PR. Not surveyed this run. |
| uptime-kuma | — | UPTODATE | none | | | | Up-to-date. No open PR. Not surveyed this run. |
Addendum
- lasuite-meet's live CI has diverged from the run's verdict: the upgrade-all summary records GREEN at build #1272 on head b3cd1aeb (v1.27.0), but the live Gitea commit status now shows RED at build #1273 on a different head (163fbcd617, PR title reverted to v1.26.0). The PR's current head is NOT the verified-green one — re-verify before merging. The subagent had already reverted to v1.26.0 once (RED #1269/#1270); the orchestrator corrected it, but the head moved again afterward.
- The advisory scan block was missing from 5 of the 6 this-run upgrade logs (only mailu carried one). I ran cc-ci-plan/advisory-scan.py independently for lasuite-drive, lasuite-meet, matrix-synapse, mattermost-lts, and n8n to get real CVE counts — mattermost-lts returned 11. The scan should run for every upgraded recipe; its absence is a tooling gap.
- gitea #7's CVE count changed between runs: the 2026-08-14 scan found 0 (GitHub Security Advisories had not yet published the GHSAs); a fresh scan today finds 7 (5 high). Advisory databases lag vendor disclosures — re-scanning open PRs at report time catches CVEs that appeared after the upgrade run. This is the scan working as designed, but it means a PR's CVE count can increase after it was opened.
- hedgedoc #3 is RED at build #1266 — the Drone clone step fails with exit 128, a drone-runner-exec infrastructure issue that hit multiple recipes in this window (bluesky-pds, ghost, gitea all saw clone failures before succeeding). The one-line pgautoupgrade 16→17 bump is not a recipe regression, and cc-ci tests use SQLite so the PG bump isn't exercised. Merge after the infra recovers.
- Four recipes carry two open PRs each to reconcile: gitea (#7 upgrade + #4 app.ini config-volume fix), bluesky-pds (#3 upgrade + #4 routing fix), mailu (#7 upgrade + #3 backupbot-labels feature), mattermost-lts (#2 upgrade + #1 restore fix, now folded into #2). Decide which of each pair lands.
- mattermost-lts #2 is a major version jump (10→11) on the LTS recipe — flagged in the PR body for operator review before merge. It also bundles a pg_backup restore fix (the prior recipe's restore was a no-op: file-level PGDATA restore did not reload into the running postgres). Postgres is held at 15-alpine; 16+ is available but too risky for an unattended run.
- immich #4 is superseded — the recipe is up-to-date at v3.1.0 after the upstream mirror sync, and PR #4 upgrades to that same version. The PR remains open and can be closed.
- Two subagents ran this run (lasuite-drive, lasuite-meet); both completed the substantive work but mis-reported — drive exhausted its turn budget before emitting a RESULT line, and meet reverted to a broken v1.26.0 head after pushing the green v1.27.0. The orchestrator verified and corrected both independently via the Gitea PR API + Drone verdicts + swarm stack-leak checks. The remaining recipes were completed directly after subagents proved unreliable on judgment/reporting.
Security Bulletin
🔒 Critical CVE upgrades
gitea 1.27.2 — five high-severity CVEs (high) · git server, likely internet-facing
gitea 1.27.1 → 1.27.2 fixes seven CVEs confirmed by GitHub Security Advisories, five of them high-severity: CVE-2026-73278, CVE-2026-73535, CVE-2026-73539, CVE-2026-73800, CVE-2026-73804 (plus two medium: CVE-2026-60008 and CVE-2026-73814). The deterministic scan run during the 2026-08-14 upgrade found 0 — the GHSAs were published only afterward; a fresh scan today finds all seven. PR #7 also bumps postgres 15.18 → 15.19, which the PostgreSQL release notes say fixes 20+ additional CVEs (the scan did not classify these — treat the 7 as a floor). !testme GREEN at build #1263. As a git server it is likely internet-facing; prioritise this merge. (The two CVSS-9.8 RCEs from 1.27.1 — CVE-2026-59774, CVE-2026-60004 — were already fixed in 1.27.1, the prior version, so they are not counted here.)
The pds 0.4.219 → 0.4.5027 upgrade moves the base image from Node 20 to Node 24.18, which patches five Node.js CVEs — two high-severity: CVE-2026-48618 (TLS wildcard-depth authentication bypass) and CVE-2026-48933 (WebCrypto AES integer overflow crash) — plus three medium (CVE-2026-48928/48930/48934 TLS/SNI identity verification bypasses, CVE-2026-48619 unbounded HTTP/2 memory growth via ORIGIN frames). The deterministic scan found 0 app-repo CVEs; these came from release-note reading of the Node 24.18 security release. No data migrations; the entrypoint change (index.js → index.ts) is handled by the recipe. !testme GREEN at build #1260 (builds #1257/#1259 were infra flakes).
What changed
1.27.1-rootless → 1.27.2-rootless + postgres 15.18 → 15.19. Seven CVEs confirmed by GitHub Security Advisories (five high: CVE-2026-73278/73535/73539/73800/73804; two medium: CVE-2026-60008/73814). The scan run during the 2026-08-14 upgrade found 0 — the GHSAs were published only afterward; a fresh scan today finds all seven. Postgres 15.19 also fixes 20+ CVEs per the PG release notes (unclassified by the scan — treat 7 as a floor). No breaking changes, no migrations. Also open: fix PR #4 (seed app.ini into a writable config volume for Gitea 1.24+, GREEN #1250).
0.4.219 → 0.4.5027. Node 20→24 base image (TypeScript entrypoint, new 0.4.<minor><patch> tag scheme). Five Node.js CVEs fixed via the Node 24.18 bump: two high (CVE-2026-48618 TLS wildcard-depth auth bypass, CVE-2026-48933 WebCrypto AES overflow) + three medium (CVE-2026-48928/48930/48934 TLS/SNI bypasses, CVE-2026-48619 HTTP/2 memory growth). No data migrations; env interface unchanged. CI needed 3 runs (2 infra flakes, 3rd GREEN #1260). Also open: fix PR #4 (rename main service app→pds so caddy resolves the stack on a shared proxy, CI pending).
10.11.22 → 11.10.0. Eleven CVEs fixed (all medium/low, counted by NVD patched-version ranges: CVE-2025-11776, CVE-2025-41436, CVE-2025-55070, CVE-2026-2578, CVE-2026-26304, CVE-2026-3117, CVE-2026-5163, CVE-2026-6339, CVE-2026-6341, CVE-2026-6342, CVE-2026-9597). This is a major LTS jump (10→11) — operator review before merge. Postgres held at 15-alpine (16+ available, too risky unattended). Bundles a pg_backup restore fix: the prior recipe shipped no restore hook, so a restored backup silently kept the live (un-restored) state; the fix makes restore actually reimport the dump. Fix PR #1 (the standalone restore fix) is folded into #2. GREEN #1277.
6.45.0-alpine → 6.57.1-alpine. Nine CVEs fixed (all medium, fixed by v6.54.1: CVE-2026-70588 through 70596, each with a GHSA). MySQL stays at 8.4 (Ghost doesn't support 9.x). No breaking changes, no migrations. CI needed 3 runs (2 drone-runner-exec infra flakes, 3rd GREEN #1261).
Sidecar-only: pgautoupgrade 16-alpine → 17-alpine (app stays at 1.11.1). Zero CVEs (scan: 6 sources, clean). CI RED at #1266 — clone step exit 128, a drone-runner-exec infrastructure issue affecting multiple recipes in this window, not a recipe regression. cc-ci tests use the SQLite backend, so the PG bump isn't exercised by CI. The PG 16→17 major upgrade is handled automatically by pgautoupgrade on container startup. Merge after infrastructure recovers.
v0.19.0 → v0.21.0 + redis 8.8.0→8.10.0, nginx 1.31.2→1.31.3, collabora 25.04.9.4.1→25.04.10.3.1, onlyoffice 9.3.1.2→9.4.1.2. Zero CVEs (scan: 24 sources, clean). PR #6 extended (not duplicated). GREEN #1267. Subagent completed the work but exhausted its turn budget before reporting; outcome verified independently via Gitea PR API + swarm stack check.
v1.25.2 → v1.27.0 (app/backend/celery monorepo set — move together). Zero CVEs (scan: 15 sources, clean). livekit, redis, nginx already latest — untouched. The subagent first pushed v1.27.0 (GREEN #1268), then reverted to v1.26.0 (RED #1269/#1270); the orchestrator reset to the verified-green v1.27.0 head (GREEN #1272). However, the live PR head has since moved again (to 163fbcd617, title reverted to v1.26.0) and the latest build #1273 is RED — re-verify before merge.
2024.06.57 → 2024.06.58 (all 6 services: nginx, admin, dovecot, postfix, rspamd, webmail). Zero CVEs identified by scan (47 sidecar advisories unclassified — a floor). redis 8.10.0 and traefik-certs-dumper v2.11.4 already latest. GREEN #1274. Also open: feat PR #3 (add backupbot v2 backup labels for admin sqlite /data + imap mail /mail, old GREEN #483).
synapse v1.157.1 → v1.158.0 + MAS 1.21→1.22 + mautrix-telegram v0.2606→v0.2607. Zero CVEs (scan: 24 sources, clean). Bridge DBs (telegram/signal/discord) held at postgres 13-alpine — multi-major jump too risky for an unattended run. PR #5 rebased clean (was mergeable=False with 5 conflicted commits; rebuilt as a single clean commit on current main). GREEN #1276.
2.34.4 → 2.35.3. Zero CVEs (scan: 9 sources, clean). Single-service patch bump within the 2.x line; postgres unchanged at 18. No required migrations. GREEN #1278.
static-web-server 2.43.0 → 2.44.0. Four security advisories from the upstream release notes (GHSA-cg27-w6jh-934r pre-compressed Moderate, GHSA-97q6-jph8-rxgm metrics Moderate, GHSA-cx3m-fg6q-xf3v basic-auth Low, GHSA-4wf2-76p9-xrmx markdown Low) — no CVE IDs assigned, so the deterministic scan counts 0. v2 is now LTS (bug + security fixes only; v3 is the new active line). GREEN #1159 (bridge-bypass — the ccci-bridge had a stale Gitea token at the time).
impress v5.2.1→v5.4.1 + redis 8.8→8.10 + nginx 1.31.1→1.31.3 + minio 2025-05-24→2025-09-07. Zero CVEs (scan: 18 sources, clean). Recipe now up-to-date; PR #7 (prior run) re-verified GREEN #1214. 123 sidecar advisories unclassified (old nginx/redis CVEs, not in window). minio is at the newest Docker Hub tag (a newer GitHub release exists but no container image was published for it).
Up-to-date at v3.1.0 — all images (server, machine-learning, postgres, valkey) at their latest supported versions per
immich's official pin matrix. PR #4 (upgrade to v3.1.0) is superseded: upstream main already carries v3.1.0 after the mirror sync. The PR remains open and can be closed. CI was GREEN #1211 (prior run).
Skipped — dirty worktree (a tracked abra.sh change: CLICKHOUSE_USER_CONF_VERSION v2→v3) plus app up-to-date (
plausible/analytics v2.0.0 is latest). Open PR #5 is a revert (restore sleep 10, needed for the pgautoupgrade window), GREEN #1253 — not an upgrade. The dirty worktree change should be committed or stashed so the recipe is surveyable next run.