Co-op Cloud Recipe CI · Weekly Edition
The Recipe Report
Week of August 28, 2026report.ci.commoninternet.net2026-08-28 04:41 UTC
Infra, not the recipes, defines the week: the *.ci.commoninternet.net wildcard Let's Encrypt cert expired 2026-08-24, so every !testme trigger died with a certificate-verify failure and no CI run could start — for any recipe. The six upgrades opened this week (discourse, lasuite-docs, lasuite-drive, lasuite-meet, mattermost-lts, n8n) were each verified by a live direct --chaos deploy on cc-ci before the PR opened, so the work itself is sound and only the CI gate is blocked — renew the cert, then re-!testme. Address the cert first; then merge the green CVE carry-overs (ghost's nine-CVE bump is still green from 2026-08-21) and re-test the blocked security PRs — lasuite-meet (three high nginx CVEs plus a redis flaw) and discourse (eight security fixes) first. Bright spot: keycloak's critical unauthenticated account-takeover CVE-2026-18963 is already patched fleet-wide, shipped in 26.7.2 a week ago.
The full wire — every recipe, in priority order
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|
| mattermost-lts | 10.11.22 → 11.7.10 | BLOCKED | 13 | no run · cert expired | #2 | … | ESR upgrade PR extended this week 11.7.9 → 11.7.10 (0 new CVEs); the 13 CVEs are the 10.11.22 → 11.7.9 ESR move it already carries (per 2026-08-21). Deploy-verified (HTTP 200, migrations ran); CI blocked by the expired cert. Reconcile with fix PR #1 (pg-restore, green build 901). |
| ghost | 6.45.0-alpine → 6.59.0-alpine | GREEN | 9 | build 1292 ✓ | #7 | … | Nine CVEs per the 2026-08-21 scan; unchanged head, still green at build 1292 — merge-ready now. Caveat: Ghost 6.60.0 is released, so #7 is behind upstream (see Addendum). |
| discourse | 2026.7.1 → 2026.7.2 | BLOCKED | 8 | no run · cert expired | #9 | … | Patch on the 2026.7 ESR line; changelog counts 8 security fixes (no CVE IDs/severities published). Rails migrations auto-run on boot; no config change. Deploy-verified; CI blocked by the expired cert. (CVE-2025-53016 low, HTML injection, no published fix — unconfirmed, not counted.) |
| lasuite-meet | v1.21.0 → v1.29.0 | BLOCKED | 4 | no run · cert expired | #9 | … | PR extended to v1.29.0 + livekit v1.13.6; crosses nginx 1.31.2 → 1.31.4 (3 high CVEs: CVE-2026-42533/56434/60005) and redis 8.8.0 → 8.10.1 (CVE-2026-62356, high). No breaking changes; AUTO_MIGRATIONS. Deploy-verified; CI blocked. Highest-value security merge once re-tested. |
| lasuite-docs | v5.4.1 → v5.5.0 | BLOCKED | none | no run · cert expired | #8 | … | impress frontend/backend/celery/y-provider minor feature release; no breaking changes, no CVEs; AUTO_MIGRATIONS. Deploy-verified (9/9 services, HTTP 200); CI blocked by the expired cert. |
| lasuite-drive | v0.21.0 → v0.21.2 | BLOCKED | none | no run · cert expired | #7 | … | Two bugfix patches (malware re-analysis + slot exhaustion); no CVEs, no migrations. Deploy-verified (11/11 services); CI blocked by the expired cert. Prior PR #6 was merged upstream and closed. |
| n8n | 2.34.4 → 2.37.3 | BLOCKED | none | no run · cert expired | #7 | … | PR extended 2.36.3 → 2.37.3 (feature minor: Agent Builder, SharePoint node v2, Anthropic prompt caching + hardening); no CVEs. 2.37.x is pre-release upstream (established newest-tag precedent). Deploy-verified (TypeORM migrations clean, healthz ok); CI blocked. Earlier heads were green before the cert expired. |
| matrix-synapse | v1.157.1 → v1.159.0 | GREEN | none | build 1298 ✓ | #5 | … | synapse v1.159.0, MAS 1.23.0, maut-* bridges, nginx already 1.31.4. Carry-over, green at build 1298 — merge-ready. |
| custom-html | 1.31.3 → 1.31.4 | GREEN | none | build 1291 ✓ | #7 | … | nginx 1.31.3 → 1.31.4; the high nginx CVE batch was already fixed in 1.31.3 (in main), so this PR adds 0 CVE fixes. Carry-over, green at build 1291 — merge-ready. |
| custom-html-tiny | → 2.44.0 | GREEN | none | build 1159 ✓ | #9 | … | static-web-server → 2.44.0. Carry-over, green at build 1159 — merge-ready. |
| hedgedoc | db 16-alpine → 18-alpine | GREEN | none | build 1302 ✓ | #3 | … | pgautoupgrade 16-alpine → 18-alpine DB-major bump (pgautoupgrade handles in-place). Carry-over, green at build 1302 — merge-ready. |
| wordpress | 7.0.4 → 7.1.0 | GREEN | none | build 1301 ✓ | #1 | … | wordpress 7.0.4 → 7.1.0. Carry-over, green at build 1301 — merge-ready. |
| plausible | clickhouse → 23.4.6.25-alpine | GREEN | none | build 1286 ✓ | #5 | … | clickhouse 23.4.6.25-alpine (23.4 LTS patch). Carry-over, green at build 1286 — merge-ready. Omitted from the 2026-08-28 upgrade-all summary (see Addendum). |
| immich | → v3.1.0 | GREEN | none | build 1211 ✓ | #4 | … | immich-server + machine-learning → v3.1.0; the postgres pin matches immich v3.1.0's released compose. Carry-over, green at build 1211 — merge-ready. |
| gitea | — | GREEN | none | build 1250 ✓ | #4 | … | A fix, not an upgrade: seeds app.ini into a writable config volume for Git over SSH. Green at build 1250. |
| mailu | — | GREEN | none | build 483 ✓ | #3 | … | A feature, not an upgrade: adds backupbot v2 backup labels (admin sqlite /data). Green at build 483. App is up-to-date at 2024.06.58. |
| keycloak | — | UPTODATE | none | | | | Up-to-date at 26.7.2 (released 2026-08-21). The critical CVE-2026-18963 (CVSS 9.1, unauthenticated account takeover) + 7 other high fixes are already patched fleet-wide (warm-keycloak runs 26.7.2). No PR — opening one would duplicate upstream. |
| bluesky-pds | — | UPTODATE | none | pending | #4 | … | App up-to-date (pds 0.4.5027). Open routing-fix PR #4 (rename app→pds so caddy resolves) has no CI verdict — pending, and now also cert-blocked. |
| cryptpad | — | UPTODATE | none | | | | Up-to-date at 2026.5.1 (latest upstream release). |
| drone | — | UPTODATE | none | | | | Up-to-date at 2.28.2. |
| mumble | — | UPTODATE | none | | | | Up-to-date at v1.6.870-0. |
Addendum
- The *.ci.commoninternet.net wildcard Let's Encrypt cert expired 2026-08-24 (operator-renewed out-of-band, ~90 days) and has not yet been renewed. It breaks the bridge's !testme → drone trigger — every trigger this run died with a certificate-verify failure, so no CI run could start for any recipe. The 3-run !testme budget was deliberately not spent on an infra block. Renew the cert (re-sops wildcard_cert/wildcard_key, commit, rebuild cc-ci so activation re-writes the live certs, deploy-proxy reconciles the swarm secret), then re-!testme the six blocked PRs. This is the single highest-impact action this week — it unblocks every recipe's CI at once.
- plausible is absent from the 2026-08-28 upgrade-all summary entirely — neither under the upgrades nor the skipped list — yet it carries an open green PR #5 (clickhouse → 23.4.6.25-alpine, 23.4 LTS patch, build 1286). The summary's 20-recipe count missed it; worth fixing the survey so a recipe with an open green PR is never dropped from the run's accounting.
- ghost PR #7 is green (build 1292, nine CVEs) but stops at 6.59.0-alpine while Ghost 6.60.0 is now released — the summary itself notes 'app at latest 6.60.0'. Worth extending #7 to 6.60.0 (or confirming 6.59.0 is the intended stop) before merge.
- mattermost-lts holds two open PRs to reconcile: #2 (the 11.7.10 ESR upgrade, CI-blocked) and #1 (a postgres-restore fix, green at build 901). Decide which lands; the restore fix is a candidate to fold into #2.
- recipe-report.py survey() reads GITEA_URL straight from .testenv with no default, so it KeyErrors when the creds file omits the host (as it did this run); publish() already defaults it to git.autonomic.zone. A one-line .get('GITEA_URL','git.autonomic.zone') at line 71 would make survey match line 295 and stop it failing on a creds file that doesn't list the host.
Security Bulletin
🔒 Critical CVE upgrades
lasuite-meet — nginx 1.31.4 high batch + redis 8.10.1 flaw (high) · CI-blocked
lasuite-meet PR #9 (v1.21.0 → v1.29.0) crosses nginx 1.31.2 → 1.31.4 and redis 8.8.0 → 8.10.1, picking up the three high nginx flaws fixed in 1.31.3 — CVE-2026-42533 (heap buffer overflow in map+regex processing → arbitrary code), CVE-2026-60005 (uninitialized-memory read via unnamed regex captures), CVE-2026-56434 (SSI use-after-free) — plus redis CVE-2026-62356 (a miscalculated buffer size in CMSketch RDB loading → heap out-of-bounds write). Both are sidecars: the nginx flaws sit in the reverse proxy, the redis flaw in the cache. The upgrade was deploy-verified (all services converged, migrations ran, HTTP 200) but !testme is blocked by the expired wildcard cert — renew it, re-test, then merge; this is the highest-value security PR of the week.
custom-html,
custom-html-tiny and
matrix-synapse already run nginx 1.31.3+, so those fixes already landed for them.
keycloak 26.7.2 — CVE-2026-18963 critical account-takeover + seven more (high) · already patched
keycloak 26.7.1 → 26.7.2 (released 2026-08-21) ships eight critical/high fixes across OIDC token handling, SAML, WebAuthn, LDAP and the admin REST API — notably CVE-2026-18963 (CVSS 9.1, unauthenticated account takeover via the reset-credentials flow bypass) and a predictable account-linking hash enabling takeover via a malicious OIDC client. Good news: this is already done. The bump landed upstream, the mirror synced, and the canonical warm-keycloak stack runs 26.7.2 — so the fleet is protected. No PR this week (opening one would duplicate upstream); listed here so a reader scanning for the critical CVE sees it is covered.
discourse — eight vendor security fixes on 2026.7.2 (severity undisclosed) · CI-blocked · internet-facing
discourse PR #9 (2026.7.1 → 2026.7.2) is a patch on the 2026.7 ESR line whose changelog counts eight security fixes (eighteen 'Security' category changes). Discourse does not assign CVE IDs or publish severities for these, so they can't be ranked here — but as an internet-facing forum they're worth treating as prompt. Rails migrations run automatically on boot; no config change. Deploy-verified via --chaos (converged, HTTP 200); !testme blocked by the expired cert. One further case, CVE-2025-53016 (low, HTML injection in solved posts), has no published fix version and could not be confirmed fixed or not by 2026.7.2 — not counted in the eight.
What changed
PR #2 extended 11.7.9 → 11.7.10 on the 11.7 ESR line (EOL 2027-05-15) — a bugfix patch adding 0 new CVEs; the PR already carries the 10.11.22 → 11.7.9 ESR move (13 CVEs, per the 2026-08-21 scan). DB major held at postgres 15-alpine (16+ is a separate operator dump/restore). Deploy-verified (HTTP 200, DB migrations ran); CI blocked by the expired cert. Reconcile with fix PR #1 (postgres-restore, green build 901); after merge, release with `abra recipe release
mattermost-lts -x` (major 10 → 11).
6.45.0-alpine → 6.59.0-alpine, carrying nine CVEs from the 2026-08-21 scan. Unchanged since — still green at build 1292, merge-ready. Caveat: Ghost 6.60.0 is now released, so #7 is behind upstream; worth extending to 6.60.0 before merge.
2026.7.1 → 2026.7.2, a patch on the 2026.7 ESR line shipping eight vendor security fixes (no CVE IDs published). Rails migrations run automatically on boot; no config/env change; redis 8.10-alpine and postgres pg18 are up-to-date. Deploy-verified (--chaos: converged, migrations ran, HTTP 200); !testme blocked by the expired cert.
PR #9 extended to v1.29.0 (app/backend/celery), plus livekit v1.13.1 → v1.13.6, redis 8.8.0 → 8.10.1, nginx 1.31.2 → 1.31.4. The nginx + redis bumps bring four CVEs (three high nginx: CVE-2026-42533/56434/60005; redis CVE-2026-62356, high). No breaking changes; AUTO_MIGRATIONS handles the DB. Deploy-verified (7/7 services, migrations applied, HTTP 200); CI blocked by the expired cert. Highest-value security merge once re-tested.
v5.4.1 → v5.5.0 across the four impress services (frontend/backend/celery/y-provider). A minor feature release — skip-to-content, i18n locales, backend profile/conditional-email APIs — with no breaking changes, no new required env vars, and AUTO_MIGRATIONS only. 0 CVEs. Deploy-verified (9/9 services, HTTP 200); CI blocked by the expired cert.
v0.21.0 → v0.21.2 across frontend/backend/celery/celery-beat — two bugfix patches (malware re-analysis of an already-scanned file; malware-analysis slot-exhaustion fix + admin actions). No CVEs, no config/env changes, no migrations. Deploy-verified (11/11 services); CI blocked by the expired cert. Prior PR #6 (the 2026-08-21 run) was merged upstream and closed.
PR #7 extended 2.36.3 → 2.37.3 (full PR span 2.34.4 → 2.37.3). A feature minor — Agent Builder/AIA, SharePoint node v2 = default, Slack Agent view, Anthropic prompt caching, agent + community-package hardening — with two API behavior changes (JSON content-type on decorator routes) that affect HTTP API callers, not the deploy. 0 CVEs. 2.37.x is pre-release upstream (the established newest-tag precedent for
n8n on cc-ci). Deploy-verified (~90 TypeORM migrations clean, healthz ok); CI blocked by the expired cert. Earlier heads were green before the cert expired.
synapse v1.157.1 → v1.159.0, MAS 1.23.0, maut-* bridges, nginx already 1.31.4. Carry-over from 2026-08-21 — green at build 1298, merge-ready.
nginx 1.31.3 → 1.31.4. The high nginx CVE batch was already fixed in 1.31.3 (in main), so this PR adds 0 CVE fixes — it's a routine follow-on patch. Carry-over, green at build 1291, merge-ready.
static-web-server → 2.44.0. Carry-over, green at build 1159, merge-ready.
pgautoupgrade 16-alpine → 18-alpine — a DB-major bump handled in-place by pgautoupgrade. Carry-over, green at build 1302, merge-ready.
wordpress 7.0.4 → 7.1.0. Carry-over, green at build 1301, merge-ready.
clickhouse → 23.4.6.25-alpine (23.4 LTS patch). Carry-over, green at build 1286, merge-ready. Notably omitted from the 2026-08-28 upgrade-all summary (see Addendum).
immich-server + machine-learning → v3.1.0; the postgres pin matches
immich v3.1.0's released compose exactly. Carry-over, green at build 1211, merge-ready.
A fix, not an upgrade: seeds app.ini into a writable config volume so Git over SSH works. Green at build 1250.
A feature, not an upgrade: adds backupbot v2 backup labels (admin sqlite /data). Green at build 483. The app itself is up-to-date at 2024.06.58.
A routing fix, not an upgrade: renames the main service app → pds so caddy resolves it. App is up-to-date (pds 0.4.5027). No CI verdict — pending, and now also blocked by the expired cert.