Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of August 21, 2026report.ci.commoninternet.net2026-08-23 01:29 UTC

A clean, security-heavy run: all eleven upgrades are !testme GREEN with zero failures, and the headline item — keycloak 26.7.2 with eight critical/high fixes (unauthenticated account-takeover via the reset-credentials bypass, FGAP bypass, Vault-resolved client-secret leak) — has already landed upstream as 10.9.2+26.7.2. Of the rest, address the nginx 1.31.3 security batch first (lasuite-docs, lasuite-drive, lasuite-meet: heap-overflow → arbitrary code, SSI use-after-free, uninitialized-memory read) and the required mattermost 10.11→11.7.9 ESR migration — 10.11 ESR ended 2026-08-15 — then the routine green bumps.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
keycloak26.7.1 → 26.7.2GREEN8build 1293 ✓#7…Identity provider — eight critical/high fixes: unauthenticated account-takeover via the reset-credentials flow bypass (CVE-2026-18963), predictable account-linking hash → takeover via a malicious OIDC client (CVE-2026-15571), FGAP bypass via the role-groups admin endpoint (CVE-2026-14613), hidden parent-group disclosure under FGAP v2 (CVE-2026-15945), Vault-resolved rotated client-secret leak from the admin REST API (CVE-2026-17048), plus jackson-databind (CVE-2026-59888/59889) and an OpenTelemetry SDK unbounded-memory flaw (CVE-2026-45292); Quarkus 3.33.3.1 bump. PR #7 closed after the upgrade landed upstream as 10.9.2+26.7.2 — the fixes are in. MariaDB 12.3 unchanged.
lasuite-docsv5.2.1 → v5.4.1GREEN6build 1294 ✓#7…nginx 1.31.1 → 1.31.4 crosses the 1.31.2 + 1.31.3 security batch — six CVEs: map+regex heap-overflow → arbitrary code (CVE-2026-42533), SSI use-after-free (CVE-2026-56434), uninitialized-memory read via unnamed regex captures (CVE-2026-60005), plus the 1.31.2 trio (CVE-2026-42055/42530/48142). Also impress v5.2.1→v5.4.1, redis 8.8.0→8.10.1, minio RELEASE.2025-09-07. Ready to merge.
lasuite-drivev0.19.0 → v0.21.0GREEN4build 1295 ✓#6…nginx 1.31.2 → 1.31.4 brings the 1.31.3 security trio (CVE-2026-42533/56434/60005) + redis 8.8.0→8.10.1 (CVE-2026-62356 heap OOB; redis is a sidecar cache). Also drive v0.21.0 (new migrations core.0025–0028, auto-run via AUTO_MIGRATIONS), collabora 25.04.10.3.1, onlyoffice 9.4.1.2. Ready to merge.
lasuite-meetv1.21.0 → v1.27.0GREEN4build 1296 ✓#9…nginx 1.31.2 → 1.31.4 (same 1.31.3 security trio) + redis 8.8.0→8.10.1 (CVE-2026-62356, sidecar cache). Also meet v1.27.0, livekit v1.13.1→v1.13.5. A pre-existing livekit→redis DNS-resolution log noise (STACK_NAME hostname not resolving in third-party DNS) is unrelated to the bump. Ready to merge.
mailu2024.06.57 → 2024.06.58GREEN1build 1297 ✓#7…redis 8.10.0 → 8.10.1 security release (CVE-2026-62356 CMSketch RDB heap OOB write; 8.10.1 also closes a malicious-RDB SLOT_INFO → memory-corruption → RCE path and a TLS client-cert NUL-truncation auth bypass — no CVE ids; redis is a sidecar cache). mailu 2024.06.57→58 is a roundcube 1.6.18 patch bump. Internet-facing mail. Separate open PR #3 (backupbot v2 labels) awaits its own decision. Ready to merge.
mattermost-lts10.11.22 → 11.7.9GREEN13build 1300 ✓#2…Required ESR migration: 10.11 ESR ended 2026-08-15, so 10→11 is necessary; 11.7.9 is the current ESR/LTS (EOL 2027-05-15) carrying 'Low to High severity' fixes — 13 CVEs counted (medium/low). postgres HELD at 15-alpine (DB-major is operator-guided). PR #2 was re-targeted off the innovation 11.10 line onto the correct LTS 11.7.9 (branch name still reads 10.11.19 — misleading). Separate fix PR #1 (pg-restore) open. Release with -x (major).
ghost6.45.0-alpine → 6.59.0-alpineGREEN9build 1292 ✓#7…Nine medium Ghost CVEs (GHSA-listed, all fixed in 6.54.1) across 6.45→6.59. New media editor (WASM libvips, AVIF/HEIC), responsive site-editor styling. MySQL held at 8.4 LTS (Ghost supports only MySQL 8; abra's 9.x/26.x candidates are false positives). No breaking changes. Ready to merge.
matrix-synapsev1.157.1 → v1.159.0GREENnonebuild 1298 ✓#5…Routine point releases: synapse v1.159.0, MAS 1.23.0, mautrix-telegram v0.2608.0 (API layer 228), nginx 1.31.3→1.31.4 (bugfixes only — no security entries). Bridge DBs already at 16-alpine on the PR. No breaking config changes. Ready to merge.
custom-html1.31.3 → 1.31.4GREENnonebuild 1291 ✓#7…nginx 1.31.3 → 1.31.4 (bugfix/feature release — no security entries; the 1.31.3 fixes were already in). Drop-in for static serving. Ready to merge.
n8n2.34.4 → 2.36.3GREENnonebuild 1299 ✓#7…n8n 2.36.0 minor (agent sandboxes + writable workspaces, MCP tools, Confluence Cloud OAuth2, Schedule Trigger catch-up) plus 2.36.2/2.36.3 patches. No breaking compose/env changes; TypeORM migrations auto-run. 2.36.x is marked Pre-release upstream but tracking the newest tag matches prior practice. Ready to merge.
wordpress7.0.4 → 7.1.0GREENnonebuild 1301 ✓#1…WordPress 7.1 'Mary Lou' minor — responsive site-editor styling, browser-side WASM libvips image processing (AVIF/HEIC/HDR gain map), new media editor, Playlist/Tabs blocks. No DB/config breaking changes; in-place. MariaDB 12.3 unchanged. Ready to merge.
hedgedocdb 16-alpine → 18-alpineGREENnonebuild 1302 ✓#3…Sidecar db bump pgautoupgrade 16→18-alpine (pg_upgrade auto-runs on first boot — may take longer). App unchanged at 1.12.0 — upstream main already ships 3.2.0+1.12.0. The upgrade-all summary mis-filed hedgedoc as 'skipped: dirty-worktree'; the run actually reconciled the mirror and produced this green PR. cc-ci tests use SQLite, so the postgres bump isn't exercised by the suite. Ready to merge.
custom-html-tiny→ 2.44.0GREENnonebuild 1159 ✓#9…static-web-server → 2.44.0. A prior-run upgrade PR (build 1159), still open and green — the summary lists custom-html-tiny as 'up-to-date' but this PR awaits merge. Merge or explicitly close.
plausibleclickhouse → 23.4.6.25-alpineGREENnonebuild 1286 ✓#5…clickhouse 23.4 LTS patch bump (23.4.x → 23.4.6.25-alpine). plausible is no longer in the 20-recipe weekly survey set, but this open green PR (build 1286) awaits a merge/close decision. No advisory scan ran this run (off-rotation).
gitea—UPTODATEnonebuild 1250 ✓ · fix PR#4…Up-to-date — gitea 1.27.2-rootless current; postgres 15.19 current within its major (cross-major 16/17/18 held, needs an operator pg_upgrade). Open fix PR #4 (seed app.ini into a writable config volume for Gitea 1.24+) is green at build 1250, unrelated to an upgrade.
immich—UPTODATEnonebuild 1211 ✓ · superseded#4…Up-to-date at v3.1.0 (latest GitHub release 2026-07-29); the DB pin matches immich v3.1.0's official pin. Open PR #4 (upgrade to v3.1.0) is functionally superseded — upstream main ships v3.1.0 — but still diverges on database (pgvectors 0.3.0 vs 0.2.0) and redis (valkey:9 digest) pins. Operator decides merge vs close. abra still can't parse the tag+digest pins (surveyed via direct cross-check).
bluesky-pds—UPTODATEnonepending#4…Up-to-date — reconcile showed 0.4.5027 already shipped upstream (the survey's 0.4.219 was a stale pre-reconcile mirror; old upgrade PR #3 closed as merged upstream). A new fix PR #4 (rename main service app→pds so caddy resolves this stack on a shared proxy) is open with CI pending — worth a !testme.
cryptpad—UPTODATEnoneUp-to-date.
discourse—UPTODATEnoneUp-to-date.
drone—UPTODATEnoneUp-to-date.
mumble—UPTODATEnoneUp-to-date.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

keycloak 26.7.2 — eight critical/high fixes on the identity provider (landed upstream) · keycloak
keycloak 26.7.1 → 26.7.2 ships eight security fixes spanning OIDC token handling, SAML, WebAuthn, LDAP and the admin REST API: an unauthenticated account-takeover via the reset-credentials flow bypass (CVE-2026-18963), a predictable account-linking hash enabling takeover via a malicious OIDC client (CVE-2026-15571), a FGAP bypass via the role-groups admin endpoint (CVE-2026-14613), hidden parent-group disclosure under FGAP v2 (CVE-2026-15945), Vault-resolved rotated client-secret leakage from the admin REST API (CVE-2026-17048), plus jackson-databind (CVE-2026-59888/59889) and an OpenTelemetry SDK unbounded-memory flaw (CVE-2026-45292), bundled with a Quarkus 3.33.3.1 bump. As an identity provider fronting other services this is the highest-priority merge of the week — and it has already landed upstream, published as 10.9.2+26.7.2 (mirror PR #7 closed). MariaDB 12.3 unchanged; no config changes.
nginx 1.31.2 / 1.31.3 security batch — heap overflow → arbitrary code, SSI use-after-free, uninitialized-memory read (high) · lasuite-docs, lasuite-drive, lasuite-meet
The nginx 1.31.3 release (15 Jul 2026) closed three security flaws now carried into these recipes: CVE-2026-42533 (a heap buffer overflow in map+regex processing that can yield arbitrary code), CVE-2026-60005 (uninitialized-memory read via unnamed regex captures), and CVE-2026-56434 (a use-after-free in SSI). lasuite-docs crosses both 1.31.2 and 1.31.3, so it also picks up the 1.31.2 trio (CVE-2026-42055/42530/48142) — six CVEs total; lasuite-drive and lasuite-meet were already on 1.31.2, so they cross only 1.31.3 (three each). All three ship GREEN this week. (matrix-synapse and custom-html were already on 1.31.3, so their 1.31.3→1.31.4 bump carries no security entries — 1.31.4 is bugfixes only.) These nginx instances reverse-proxy the app backends; the 1.31.3 XSLT external-entities default-off change does not apply (no XSLT filtering in any of the recipes).
redis 8.10.1 security release — CMSketch heap OOB write, malicious-RDB RCE, TLS client-cert auth bypass (high) · sidecar cache in lasuite-drive, lasuite-meet, mailu
redis 8.10.1 (17 Aug 2026) is a security release. The scanner counts CVE-2026-62356 (a miscalculated buffer size in CMSketch RDB loading → heap out-of-bounds write); the release notes additionally fix a malicious-RDB SLOT_INFO out-of-range slot id leading to memory corruption and possible RCE, a TLS client-certificate authentication bypass (a CN with an embedded NUL is truncated, allowing auth as another ACL user), Vector-Sets OOB/UAF reads, and a blocked-client list use-after-free — these have no CVE ids assigned but are high-severity. redis runs as a sidecar cache/session store in these recipes (not internet-exposed), which lowers operator exposure, but the RCE and auth-bypass paths warrant the bump. No config or migration impact. lasuite-drive and lasuite-meet move 8.8.0→8.10.1; mailu moves 8.10.0→8.10.1.

What changed

26.7.1 → 26.7.2. A security patch release: eight fixes spanning OIDC token handling, SAML, WebAuthn, LDAP and the admin REST API (account-takeover, FGAP bypass, Vault-secret leak, hidden-group disclosure, jackson-databind, OpenTelemetry), plus a Quarkus 3.33.3.1 bump. No config changes; MariaDB 12.3 unchanged. The upgrade landed upstream as 10.9.2+26.7.2 (mirror PR #7 closed).
v5.2.1 → v5.4.1. nginx 1.31.1→1.31.4 crosses the 1.31.2 + 1.31.3 security batch (six CVEs); redis 8.8.0→8.10.1; impress v5.4.1; minio RELEASE.2025-09-07. AUTO_MIGRATIONS handles the DB. Clean GREEN.
v0.19.0 → v0.21.0. nginx 1.31.2→1.31.4 (1.31.3 security trio) + redis 8.8.0→8.10.1 (CVE-2026-62356, sidecar). New migrations core.0025–0028 (auto-run); collabora 25.04.10.3.1, onlyoffice 9.4.1.2. Clean GREEN.
v1.21.0 → v1.27.0. nginx 1.31.2→1.31.4 (1.31.3 security trio) + redis 8.8.0→8.10.1 (CVE-2026-62356, sidecar) + livekit v1.13.1→v1.13.5. Backend migrations auto-run. A pre-existing livekit→redis DNS-resolution log noise is unrelated to the bump.
2024.06.57 → 2024.06.58. redis 8.10.0→8.10.1 security release (CVE-2026-62356 heap OOB; plus malicious-RDB RCE and TLS auth-bypass fixes with no CVE ids — sidecar cache). The mailu images move together as a roundcube 1.6.18 patch bump. Internet-facing. Separate open PR #3 (backupbot v2 labels).
10.11.22 → 11.7.9. A required ESR migration (10.11 ESR ended 2026-08-15; 11.7.9 is the current LTS, EOL 2027-05-15) carrying 13 medium/low CVEs. PR #2 was re-targeted off the innovation 11.10 line onto the correct LTS (branch name still misleadingly reads 10.11.19). postgres held at 15-alpine. Reconcile with fix PR #1; release with -x (major).
6.45.0 → 6.59.0-alpine. Nine medium Ghost CVEs (all fixed in 6.54.1) plus a new media editor (WASM libvips, AVIF/HEIC) and responsive site-editor styling. MySQL held at 8.4 LTS. No breaking changes. Ready to merge.
v1.157.1 → v1.159.0. Routine point releases: synapse v1.159.0, MAS 1.23.0, mautrix-telegram v0.2608.0 (API layer 228), nginx 1.31.3→1.31.4 (bugfixes only). Bridge DBs at 16-alpine on the PR. No breaking config changes.
nginx 1.31.3 → 1.31.4. Bugfix/feature release (PROXY protocol v2 in stream/mail, :authority pseudo-header for HTTP/2 backends); no security entries — the 1.31.3 fixes were already in. Drop-in for static serving. Clean GREEN.
2.34.4 → 2.36.3. 2.36.0 minor (agent sandboxes, MCP tools, Confluence Cloud OAuth2, Schedule Trigger catch-up) + 2.36.2/2.36.3 patches. No breaking compose/env changes; TypeORM migrations auto-run. 2.36.x is Pre-release upstream but tracking the newest tag matches prior practice.
7.0.4 → 7.1.0. WordPress 7.1 'Mary Lou' minor — responsive site-editor styling, browser-side WASM libvips image processing (AVIF/HEIC/HDR), new media editor, Playlist/Tabs blocks. No DB/config breaking changes; in-place. MariaDB 12.3 unchanged.
Sidecar db bump pgautoupgrade 16 → 18-alpine (pg_upgrade auto-runs on first boot). App unchanged at 1.12.0 — upstream main already ships 3.2.0+1.12.0. The summary mis-filed hedgedoc as 'skipped: dirty-worktree'; the run actually reconciled the mirror and produced this green PR. cc-ci tests use SQLite, so the postgres bump isn't exercised by the suite.
static-web-server → 2.44.0. A prior-run upgrade PR, still open and green (build 1159) — the summary lists custom-html-tiny as 'up-to-date' but this PR awaits a merge/close decision.
clickhouse 23.4 LTS patch bump (23.4.x → 23.4.6.25-alpine). plausible is no longer in the 20-recipe weekly survey set; this open green PR (build 1286) awaits a merge/close decision or re-adding plausible to the rotation. No advisory scan ran this run.
Up-to-date (gitea 1.27.2-rootless current; postgres 15.19 current within its major). Open fix PR #4 seeds app.ini into a writable config volume for Gitea 1.24+ — green at build 1250, unrelated to an upgrade. Awaits merge.
Up-to-date at v3.1.0 (latest GitHub release 2026-07-29); DB pin matches immich v3.1.0's official pin. Open PR #4 (upgrade to v3.1.0) is functionally superseded — upstream main ships v3.1.0 — but still diverges on database (pgvectors 0.3.0 vs 0.2.0) and redis (valkey:9 digest) pins. Operator decides merge vs close. abra can't parse the tag+digest pins (surveyed via direct cross-check).
Up-to-date — 0.4.5027 already shipped upstream (the survey's 0.4.219 was a stale pre-reconcile mirror; old upgrade PR #3 closed as merged upstream). A new fix PR #4 renames the main service app→pds so caddy resolves this stack on a shared proxy; CI is still pending — worth a !testme.