Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of August 28, 2026report.ci.commoninternet.net2026-08-28 04:41 UTC

Infra, not the recipes, defines the week: the *.ci.commoninternet.net wildcard Let's Encrypt cert expired 2026-08-24, so every !testme trigger died with a certificate-verify failure and no CI run could start — for any recipe. The six upgrades opened this week (discourse, lasuite-docs, lasuite-drive, lasuite-meet, mattermost-lts, n8n) were each verified by a live direct --chaos deploy on cc-ci before the PR opened, so the work itself is sound and only the CI gate is blocked — renew the cert, then re-!testme. Address the cert first; then merge the green CVE carry-overs (ghost's nine-CVE bump is still green from 2026-08-21) and re-test the blocked security PRs — lasuite-meet (three high nginx CVEs plus a redis flaw) and discourse (eight security fixes) first. Bright spot: keycloak's critical unauthenticated account-takeover CVE-2026-18963 is already patched fleet-wide, shipped in 26.7.2 a week ago.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
mattermost-lts10.11.22 → 11.7.10BLOCKED13no run · cert expired#2…ESR upgrade PR extended this week 11.7.9 → 11.7.10 (0 new CVEs); the 13 CVEs are the 10.11.22 → 11.7.9 ESR move it already carries (per 2026-08-21). Deploy-verified (HTTP 200, migrations ran); CI blocked by the expired cert. Reconcile with fix PR #1 (pg-restore, green build 901).
ghost6.45.0-alpine → 6.59.0-alpineGREEN9build 1292 ✓#7…Nine CVEs per the 2026-08-21 scan; unchanged head, still green at build 1292 — merge-ready now. Caveat: Ghost 6.60.0 is released, so #7 is behind upstream (see Addendum).
discourse2026.7.1 → 2026.7.2BLOCKED8no run · cert expired#9…Patch on the 2026.7 ESR line; changelog counts 8 security fixes (no CVE IDs/severities published). Rails migrations auto-run on boot; no config change. Deploy-verified; CI blocked by the expired cert. (CVE-2025-53016 low, HTML injection, no published fix — unconfirmed, not counted.)
lasuite-meetv1.21.0 → v1.29.0BLOCKED4no run · cert expired#9…PR extended to v1.29.0 + livekit v1.13.6; crosses nginx 1.31.2 → 1.31.4 (3 high CVEs: CVE-2026-42533/56434/60005) and redis 8.8.0 → 8.10.1 (CVE-2026-62356, high). No breaking changes; AUTO_MIGRATIONS. Deploy-verified; CI blocked. Highest-value security merge once re-tested.
lasuite-docsv5.4.1 → v5.5.0BLOCKEDnoneno run · cert expired#8…impress frontend/backend/celery/y-provider minor feature release; no breaking changes, no CVEs; AUTO_MIGRATIONS. Deploy-verified (9/9 services, HTTP 200); CI blocked by the expired cert.
lasuite-drivev0.21.0 → v0.21.2BLOCKEDnoneno run · cert expired#7…Two bugfix patches (malware re-analysis + slot exhaustion); no CVEs, no migrations. Deploy-verified (11/11 services); CI blocked by the expired cert. Prior PR #6 was merged upstream and closed.
n8n2.34.4 → 2.37.3BLOCKEDnoneno run · cert expired#7…PR extended 2.36.3 → 2.37.3 (feature minor: Agent Builder, SharePoint node v2, Anthropic prompt caching + hardening); no CVEs. 2.37.x is pre-release upstream (established newest-tag precedent). Deploy-verified (TypeORM migrations clean, healthz ok); CI blocked. Earlier heads were green before the cert expired.
matrix-synapsev1.157.1 → v1.159.0GREENnonebuild 1298 ✓#5…synapse v1.159.0, MAS 1.23.0, maut-* bridges, nginx already 1.31.4. Carry-over, green at build 1298 — merge-ready.
custom-html1.31.3 → 1.31.4GREENnonebuild 1291 ✓#7…nginx 1.31.3 → 1.31.4; the high nginx CVE batch was already fixed in 1.31.3 (in main), so this PR adds 0 CVE fixes. Carry-over, green at build 1291 — merge-ready.
custom-html-tiny→ 2.44.0GREENnonebuild 1159 ✓#9…static-web-server → 2.44.0. Carry-over, green at build 1159 — merge-ready.
hedgedocdb 16-alpine → 18-alpineGREENnonebuild 1302 ✓#3…pgautoupgrade 16-alpine → 18-alpine DB-major bump (pgautoupgrade handles in-place). Carry-over, green at build 1302 — merge-ready.
wordpress7.0.4 → 7.1.0GREENnonebuild 1301 ✓#1…wordpress 7.0.4 → 7.1.0. Carry-over, green at build 1301 — merge-ready.
plausibleclickhouse → 23.4.6.25-alpineGREENnonebuild 1286 ✓#5…clickhouse 23.4.6.25-alpine (23.4 LTS patch). Carry-over, green at build 1286 — merge-ready. Omitted from the 2026-08-28 upgrade-all summary (see Addendum).
immich→ v3.1.0GREENnonebuild 1211 ✓#4…immich-server + machine-learning → v3.1.0; the postgres pin matches immich v3.1.0's released compose. Carry-over, green at build 1211 — merge-ready.
gitea—GREENnonebuild 1250 ✓#4…A fix, not an upgrade: seeds app.ini into a writable config volume for Git over SSH. Green at build 1250.
mailu—GREENnonebuild 483 ✓#3…A feature, not an upgrade: adds backupbot v2 backup labels (admin sqlite /data). Green at build 483. App is up-to-date at 2024.06.58.
keycloak—UPTODATEnoneUp-to-date at 26.7.2 (released 2026-08-21). The critical CVE-2026-18963 (CVSS 9.1, unauthenticated account takeover) + 7 other high fixes are already patched fleet-wide (warm-keycloak runs 26.7.2). No PR — opening one would duplicate upstream.
bluesky-pds—UPTODATEnonepending#4…App up-to-date (pds 0.4.5027). Open routing-fix PR #4 (rename app→pds so caddy resolves) has no CI verdict — pending, and now also cert-blocked.
cryptpad—UPTODATEnoneUp-to-date at 2026.5.1 (latest upstream release).
drone—UPTODATEnoneUp-to-date at 2.28.2.
mumble—UPTODATEnoneUp-to-date at v1.6.870-0.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

lasuite-meet — nginx 1.31.4 high batch + redis 8.10.1 flaw (high) · CI-blocked
lasuite-meet PR #9 (v1.21.0 → v1.29.0) crosses nginx 1.31.2 → 1.31.4 and redis 8.8.0 → 8.10.1, picking up the three high nginx flaws fixed in 1.31.3 — CVE-2026-42533 (heap buffer overflow in map+regex processing → arbitrary code), CVE-2026-60005 (uninitialized-memory read via unnamed regex captures), CVE-2026-56434 (SSI use-after-free) — plus redis CVE-2026-62356 (a miscalculated buffer size in CMSketch RDB loading → heap out-of-bounds write). Both are sidecars: the nginx flaws sit in the reverse proxy, the redis flaw in the cache. The upgrade was deploy-verified (all services converged, migrations ran, HTTP 200) but !testme is blocked by the expired wildcard cert — renew it, re-test, then merge; this is the highest-value security PR of the week. custom-html, custom-html-tiny and matrix-synapse already run nginx 1.31.3+, so those fixes already landed for them.
keycloak 26.7.2 — CVE-2026-18963 critical account-takeover + seven more (high) · already patched
keycloak 26.7.1 → 26.7.2 (released 2026-08-21) ships eight critical/high fixes across OIDC token handling, SAML, WebAuthn, LDAP and the admin REST API — notably CVE-2026-18963 (CVSS 9.1, unauthenticated account takeover via the reset-credentials flow bypass) and a predictable account-linking hash enabling takeover via a malicious OIDC client. Good news: this is already done. The bump landed upstream, the mirror synced, and the canonical warm-keycloak stack runs 26.7.2 — so the fleet is protected. No PR this week (opening one would duplicate upstream); listed here so a reader scanning for the critical CVE sees it is covered.
discourse — eight vendor security fixes on 2026.7.2 (severity undisclosed) · CI-blocked · internet-facing
discourse PR #9 (2026.7.1 → 2026.7.2) is a patch on the 2026.7 ESR line whose changelog counts eight security fixes (eighteen 'Security' category changes). Discourse does not assign CVE IDs or publish severities for these, so they can't be ranked here — but as an internet-facing forum they're worth treating as prompt. Rails migrations run automatically on boot; no config change. Deploy-verified via --chaos (converged, HTTP 200); !testme blocked by the expired cert. One further case, CVE-2025-53016 (low, HTML injection in solved posts), has no published fix version and could not be confirmed fixed or not by 2026.7.2 — not counted in the eight.

What changed

PR #2 extended 11.7.9 → 11.7.10 on the 11.7 ESR line (EOL 2027-05-15) — a bugfix patch adding 0 new CVEs; the PR already carries the 10.11.22 → 11.7.9 ESR move (13 CVEs, per the 2026-08-21 scan). DB major held at postgres 15-alpine (16+ is a separate operator dump/restore). Deploy-verified (HTTP 200, DB migrations ran); CI blocked by the expired cert. Reconcile with fix PR #1 (postgres-restore, green build 901); after merge, release with `abra recipe release mattermost-lts -x` (major 10 → 11).
6.45.0-alpine → 6.59.0-alpine, carrying nine CVEs from the 2026-08-21 scan. Unchanged since — still green at build 1292, merge-ready. Caveat: Ghost 6.60.0 is now released, so #7 is behind upstream; worth extending to 6.60.0 before merge.
2026.7.1 → 2026.7.2, a patch on the 2026.7 ESR line shipping eight vendor security fixes (no CVE IDs published). Rails migrations run automatically on boot; no config/env change; redis 8.10-alpine and postgres pg18 are up-to-date. Deploy-verified (--chaos: converged, migrations ran, HTTP 200); !testme blocked by the expired cert.
PR #9 extended to v1.29.0 (app/backend/celery), plus livekit v1.13.1 → v1.13.6, redis 8.8.0 → 8.10.1, nginx 1.31.2 → 1.31.4. The nginx + redis bumps bring four CVEs (three high nginx: CVE-2026-42533/56434/60005; redis CVE-2026-62356, high). No breaking changes; AUTO_MIGRATIONS handles the DB. Deploy-verified (7/7 services, migrations applied, HTTP 200); CI blocked by the expired cert. Highest-value security merge once re-tested.
v5.4.1 → v5.5.0 across the four impress services (frontend/backend/celery/y-provider). A minor feature release — skip-to-content, i18n locales, backend profile/conditional-email APIs — with no breaking changes, no new required env vars, and AUTO_MIGRATIONS only. 0 CVEs. Deploy-verified (9/9 services, HTTP 200); CI blocked by the expired cert.
v0.21.0 → v0.21.2 across frontend/backend/celery/celery-beat — two bugfix patches (malware re-analysis of an already-scanned file; malware-analysis slot-exhaustion fix + admin actions). No CVEs, no config/env changes, no migrations. Deploy-verified (11/11 services); CI blocked by the expired cert. Prior PR #6 (the 2026-08-21 run) was merged upstream and closed.
PR #7 extended 2.36.3 → 2.37.3 (full PR span 2.34.4 → 2.37.3). A feature minor — Agent Builder/AIA, SharePoint node v2 = default, Slack Agent view, Anthropic prompt caching, agent + community-package hardening — with two API behavior changes (JSON content-type on decorator routes) that affect HTTP API callers, not the deploy. 0 CVEs. 2.37.x is pre-release upstream (the established newest-tag precedent for n8n on cc-ci). Deploy-verified (~90 TypeORM migrations clean, healthz ok); CI blocked by the expired cert. Earlier heads were green before the cert expired.
synapse v1.157.1 → v1.159.0, MAS 1.23.0, maut-* bridges, nginx already 1.31.4. Carry-over from 2026-08-21 — green at build 1298, merge-ready.
nginx 1.31.3 → 1.31.4. The high nginx CVE batch was already fixed in 1.31.3 (in main), so this PR adds 0 CVE fixes — it's a routine follow-on patch. Carry-over, green at build 1291, merge-ready.
static-web-server → 2.44.0. Carry-over, green at build 1159, merge-ready.
pgautoupgrade 16-alpine → 18-alpine — a DB-major bump handled in-place by pgautoupgrade. Carry-over, green at build 1302, merge-ready.
wordpress 7.0.4 → 7.1.0. Carry-over, green at build 1301, merge-ready.
clickhouse → 23.4.6.25-alpine (23.4 LTS patch). Carry-over, green at build 1286, merge-ready. Notably omitted from the 2026-08-28 upgrade-all summary (see Addendum).
immich-server + machine-learning → v3.1.0; the postgres pin matches immich v3.1.0's released compose exactly. Carry-over, green at build 1211, merge-ready.
A fix, not an upgrade: seeds app.ini into a writable config volume so Git over SSH works. Green at build 1250.
A feature, not an upgrade: adds backupbot v2 backup labels (admin sqlite /data). Green at build 483. The app itself is up-to-date at 2024.06.58.
A routing fix, not an upgrade: renames the main service app → pds so caddy resolves it. App is up-to-date (pds 0.4.5027). No CI verdict — pending, and now also blocked by the expired cert.