A clean, security-heavy run: all eleven upgrades are !testme GREEN with zero failures, and the headline item — keycloak 26.7.2 with eight critical/high fixes (unauthenticated account-takeover via the reset-credentials bypass, FGAP bypass, Vault-resolved client-secret leak) — has already landed upstream as 10.9.2+26.7.2. Of the rest, address the nginx 1.31.3 security batch first (lasuite-docs, lasuite-drive, lasuite-meet: heap-overflow → arbitrary code, SSI use-after-free, uninitialized-memory read) and the required mattermost 10.11→11.7.9 ESR migration — 10.11 ESR ended 2026-08-15 — then the routine green bumps.
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|
| keycloak | 26.7.1 → 26.7.2 | GREEN | 8 | build 1293 ✓ | #7 | … | Identity provider — eight critical/high fixes: unauthenticated account-takeover via the reset-credentials flow bypass (CVE-2026-18963), predictable account-linking hash → takeover via a malicious OIDC client (CVE-2026-15571), FGAP bypass via the role-groups admin endpoint (CVE-2026-14613), hidden parent-group disclosure under FGAP v2 (CVE-2026-15945), Vault-resolved rotated client-secret leak from the admin REST API (CVE-2026-17048), plus jackson-databind (CVE-2026-59888/59889) and an OpenTelemetry SDK unbounded-memory flaw (CVE-2026-45292); Quarkus 3.33.3.1 bump. PR #7 closed after the upgrade landed upstream as 10.9.2+26.7.2 — the fixes are in. MariaDB 12.3 unchanged. |
| lasuite-docs | v5.2.1 → v5.4.1 | GREEN | 6 | build 1294 ✓ | #7 | … | nginx 1.31.1 → 1.31.4 crosses the 1.31.2 + 1.31.3 security batch — six CVEs: map+regex heap-overflow → arbitrary code (CVE-2026-42533), SSI use-after-free (CVE-2026-56434), uninitialized-memory read via unnamed regex captures (CVE-2026-60005), plus the 1.31.2 trio (CVE-2026-42055/42530/48142). Also impress v5.2.1→v5.4.1, redis 8.8.0→8.10.1, minio RELEASE.2025-09-07. Ready to merge. |
| lasuite-drive | v0.19.0 → v0.21.0 | GREEN | 4 | build 1295 ✓ | #6 | … | nginx 1.31.2 → 1.31.4 brings the 1.31.3 security trio (CVE-2026-42533/56434/60005) + redis 8.8.0→8.10.1 (CVE-2026-62356 heap OOB; redis is a sidecar cache). Also drive v0.21.0 (new migrations core.0025–0028, auto-run via AUTO_MIGRATIONS), collabora 25.04.10.3.1, onlyoffice 9.4.1.2. Ready to merge. |
| lasuite-meet | v1.21.0 → v1.27.0 | GREEN | 4 | build 1296 ✓ | #9 | … | nginx 1.31.2 → 1.31.4 (same 1.31.3 security trio) + redis 8.8.0→8.10.1 (CVE-2026-62356, sidecar cache). Also meet v1.27.0, livekit v1.13.1→v1.13.5. A pre-existing livekit→redis DNS-resolution log noise (STACK_NAME hostname not resolving in third-party DNS) is unrelated to the bump. Ready to merge. |
| mailu | 2024.06.57 → 2024.06.58 | GREEN | 1 | build 1297 ✓ | #7 | … | redis 8.10.0 → 8.10.1 security release (CVE-2026-62356 CMSketch RDB heap OOB write; 8.10.1 also closes a malicious-RDB SLOT_INFO → memory-corruption → RCE path and a TLS client-cert NUL-truncation auth bypass — no CVE ids; redis is a sidecar cache). mailu 2024.06.57→58 is a roundcube 1.6.18 patch bump. Internet-facing mail. Separate open PR #3 (backupbot v2 labels) awaits its own decision. Ready to merge. |
| mattermost-lts | 10.11.22 → 11.7.9 | GREEN | 13 | build 1300 ✓ | #2 | … | Required ESR migration: 10.11 ESR ended 2026-08-15, so 10→11 is necessary; 11.7.9 is the current ESR/LTS (EOL 2027-05-15) carrying 'Low to High severity' fixes — 13 CVEs counted (medium/low). postgres HELD at 15-alpine (DB-major is operator-guided). PR #2 was re-targeted off the innovation 11.10 line onto the correct LTS 11.7.9 (branch name still reads 10.11.19 — misleading). Separate fix PR #1 (pg-restore) open. Release with -x (major). |
| ghost | 6.45.0-alpine → 6.59.0-alpine | GREEN | 9 | build 1292 ✓ | #7 | … | Nine medium Ghost CVEs (GHSA-listed, all fixed in 6.54.1) across 6.45→6.59. New media editor (WASM libvips, AVIF/HEIC), responsive site-editor styling. MySQL held at 8.4 LTS (Ghost supports only MySQL 8; abra's 9.x/26.x candidates are false positives). No breaking changes. Ready to merge. |
| matrix-synapse | v1.157.1 → v1.159.0 | GREEN | none | build 1298 ✓ | #5 | … | Routine point releases: synapse v1.159.0, MAS 1.23.0, mautrix-telegram v0.2608.0 (API layer 228), nginx 1.31.3→1.31.4 (bugfixes only — no security entries). Bridge DBs already at 16-alpine on the PR. No breaking config changes. Ready to merge. |
| custom-html | 1.31.3 → 1.31.4 | GREEN | none | build 1291 ✓ | #7 | … | nginx 1.31.3 → 1.31.4 (bugfix/feature release — no security entries; the 1.31.3 fixes were already in). Drop-in for static serving. Ready to merge. |
| n8n | 2.34.4 → 2.36.3 | GREEN | none | build 1299 ✓ | #7 | … | n8n 2.36.0 minor (agent sandboxes + writable workspaces, MCP tools, Confluence Cloud OAuth2, Schedule Trigger catch-up) plus 2.36.2/2.36.3 patches. No breaking compose/env changes; TypeORM migrations auto-run. 2.36.x is marked Pre-release upstream but tracking the newest tag matches prior practice. Ready to merge. |
| wordpress | 7.0.4 → 7.1.0 | GREEN | none | build 1301 ✓ | #1 | … | WordPress 7.1 'Mary Lou' minor — responsive site-editor styling, browser-side WASM libvips image processing (AVIF/HEIC/HDR gain map), new media editor, Playlist/Tabs blocks. No DB/config breaking changes; in-place. MariaDB 12.3 unchanged. Ready to merge. |
| hedgedoc | db 16-alpine → 18-alpine | GREEN | none | build 1302 ✓ | #3 | … | Sidecar db bump pgautoupgrade 16→18-alpine (pg_upgrade auto-runs on first boot — may take longer). App unchanged at 1.12.0 — upstream main already ships 3.2.0+1.12.0. The upgrade-all summary mis-filed hedgedoc as 'skipped: dirty-worktree'; the run actually reconciled the mirror and produced this green PR. cc-ci tests use SQLite, so the postgres bump isn't exercised by the suite. Ready to merge. |
| custom-html-tiny | → 2.44.0 | GREEN | none | build 1159 ✓ | #9 | … | static-web-server → 2.44.0. A prior-run upgrade PR (build 1159), still open and green — the summary lists custom-html-tiny as 'up-to-date' but this PR awaits merge. Merge or explicitly close. |
| plausible | clickhouse → 23.4.6.25-alpine | GREEN | none | build 1286 ✓ | #5 | … | clickhouse 23.4 LTS patch bump (23.4.x → 23.4.6.25-alpine). plausible is no longer in the 20-recipe weekly survey set, but this open green PR (build 1286) awaits a merge/close decision. No advisory scan ran this run (off-rotation). |
| gitea | — | UPTODATE | none | build 1250 ✓ · fix PR | #4 | … | Up-to-date — gitea 1.27.2-rootless current; postgres 15.19 current within its major (cross-major 16/17/18 held, needs an operator pg_upgrade). Open fix PR #4 (seed app.ini into a writable config volume for Gitea 1.24+) is green at build 1250, unrelated to an upgrade. |
| immich | — | UPTODATE | none | build 1211 ✓ · superseded | #4 | … | Up-to-date at v3.1.0 (latest GitHub release 2026-07-29); the DB pin matches immich v3.1.0's official pin. Open PR #4 (upgrade to v3.1.0) is functionally superseded — upstream main ships v3.1.0 — but still diverges on database (pgvectors 0.3.0 vs 0.2.0) and redis (valkey:9 digest) pins. Operator decides merge vs close. abra still can't parse the tag+digest pins (surveyed via direct cross-check). |
| bluesky-pds | — | UPTODATE | none | pending | #4 | … | Up-to-date — reconcile showed 0.4.5027 already shipped upstream (the survey's 0.4.219 was a stale pre-reconcile mirror; old upgrade PR #3 closed as merged upstream). A new fix PR #4 (rename main service app→pds so caddy resolves this stack on a shared proxy) is open with CI pending — worth a !testme. |
| cryptpad | — | UPTODATE | none | | | | Up-to-date. |
| discourse | — | UPTODATE | none | | | | Up-to-date. |
| drone | — | UPTODATE | none | | | | Up-to-date. |
| mumble | — | UPTODATE | none | | | | Up-to-date. |
26.7.1 → 26.7.2. A security patch release: eight fixes spanning OIDC token handling, SAML, WebAuthn, LDAP and the admin REST API (account-takeover, FGAP bypass, Vault-secret leak, hidden-group disclosure, jackson-databind, OpenTelemetry), plus a Quarkus 3.33.3.1 bump. No config changes; MariaDB 12.3 unchanged. The upgrade landed upstream as 10.9.2+26.7.2 (mirror PR #7 closed).
2.34.4 → 2.36.3. 2.36.0 minor (agent sandboxes, MCP tools, Confluence Cloud OAuth2, Schedule Trigger catch-up) + 2.36.2/2.36.3 patches. No breaking compose/env changes; TypeORM migrations auto-run. 2.36.x is Pre-release upstream but tracking the newest tag matches prior practice.
7.0.4 → 7.1.0. WordPress 7.1 'Mary Lou' minor — responsive site-editor styling, browser-side WASM libvips image processing (AVIF/HEIC/HDR), new media editor, Playlist/Tabs blocks. No DB/config breaking changes; in-place. MariaDB 12.3 unchanged.