Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of August 31, 2026report.ci.commoninternet.net2026-08-31 20:49 UTC

The cert outage that froze last week's CI is behind us — the renewed *.ci.commoninternet.net wildcard (valid to 2026-11-29) let every !testme trigger a real run, and the week comes back clean: all nine upgrade PRs are GREEN, nothing red, nothing stale, and the seven PRs stranded by the outage were extended and re-verified rather than re-opened. Address security first — gitea's 26-CVE release (Actions approval bypasses, restricted-user data leaks; five high) and keycloak's 22-fix batch on the identity provider, then mattermost-lts's 13-CVE ESR move and lasuite-meet's nginx highs plus a redis security release — after which the wire is routine bumps and merge-ready carry-overs.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
gitea1.27.2-rootless → 1.27.3-rootlessGREEN26build 1306 ✓#8…Security release: 26 CVEs — fork-PR Actions approval bypasses (code execution where self-hosted runners are enabled), restricted-user data leaks, package-registry access and token-scope fixes; five high per the vendor post. Count is a floor: CVE-2025-68939 stays unjudged. postgres 15 held (DB-major = operator dump/restore). Unrelated fix PR #4 (writable app.ini, green 1250) also open.
keycloak26.7.2 → 26.7.3GREEN22build 1307 ✓#8…Identity provider: 22 fixes — unsigned signed-JWT assertion bypass, LDAP cert hostname verification, redirect_uri / FGAP authz bypasses, PII disclosure. Deploying from ≤26.7.1 also lands critical CVE-2026-18963 (account takeover, fixed in 26.7.2 — already in main). Fresh PR after last week's #7 survey false-positive; mariadb 12.3 held; no migrations.
lasuite-meetv1.21.0 → v1.29.0GREEN4build 1311 ✓#9…Crosses nginx 1.31.2 → 1.31.4 (3 high: CVE-2026-42533/56434/60005) and redis 8.8.0 → 8.10.1 (CVE-2026-62356 heap OOB write in RDB loading — floor: 8.10.1 names more unnamed security fixes) + livekit v1.13.6. No breaking changes; migrations auto-ran. Last week's cert-blocked flag is cleared.
mattermost-lts10.11.22 → 11.7.10GREEN13build 1310 ✓#2…ESR move off the 10.11 line (EOL 2026-08-15) onto 11.7 (EOL 2027-05-15); 13 CVEs, all medium/low. postgres 15 held (separate operator step). Reconcile with fix PR #1 (pg-restore, green 901). Release is a major (-x).
discourse2026.7.1 → 2026.7.2GREENnonebuild 1303 ✓#9…Security patch on the 2026.7 ESR line: 8 security-fix groups / 18 SECURITY commits, but upstream publishes no CVE IDs (scan 0; CVE-2025-53016 adjudicated pre-existing). Migrations auto-run on boot. A duplicate !testme also spawned build 1305 — green too.
ghost6.60.0-alpine → 6.61.0-alpineGREENnonebuild 1304 ✓#7…PR #7 extended past its stale 6.59.0 target to 6.61.0 (gift subscriptions; no breaking changes). The earlier nine-CVE window landed in main via upstream's own 6.59/6.60 merges — this extension adds none. mysql held at 8.4 (Ghost supports MySQL 8 only).
lasuite-docsv5.4.1 → v5.5.0GREENnonebuild 1308 ✓#8…impress minor (a11y, new i18n locales, presenter links); AUTO_MIGRATIONS ran clean; no config changes.
lasuite-drivev0.21.0 → v0.21.2GREENnonebuild 1309 ✓#7…Two malware-analysis bugfix patches; no migrations. collabora held at 25.04 (26.04 image is shell-less — service redesign, flagged to the maintainer); minio at its Docker Hub cap.
n8n2.34.4 → 2.37.6GREENnonebuild 1312 ✓#7…Extended past 2.37.3 (2.37.5 withdrawn upstream). 2.37.x is still pre-release upstream — the stable line is 2.36.9; tracking the newest tag is the established precedent. Level 5/5 suite green.
matrix-synapsev1.157.1 → v1.159.0GREENnonebuild 1298 ✓#5…synapse v1.159.0 + MAS 1.23.0 + mautrix-telegram v0.2608.0; nginx already 1.31.4. Carry-over, green since 08-21 — merge-ready; DB majors deliberately held.
custom-html1.31.3 → 1.31.4GREENnonebuild 1291 ✓#7…nginx 1.31.3 → 1.31.4 — the high batch was fixed in 1.31.3 (already pinned in main), so 0 CVEs here. Carry-over, green since 08-21 — merge-ready.
custom-html-tiny→ 2.44.0GREENnonebuild 1159 ✓#9…static-web-server 2.44.0 (latest). Carry-over, green — merge-ready.
hedgedocdb 16-alpine → 18-alpineGREENnonebuild 1302 ✓#3…pgautoupgrade DB-major (in-place); app 1.12.0 latest. Carry-over, green since 08-22 — merge-ready.
wordpress7.0.4 → 7.1.0GREENnonebuild 1301 ✓#1…Carry-over, green since 08-21 — merge-ready.
immich→ v3.1.0GREENnonebuild 1211 ✓#4…immich-server + machine-learning v3.1.0; the postgres pin matches v3.1.0's released compose. Carry-over, green — merge-ready.
plausibleclickhouse → 23.4.6.25-alpineGREENnonebuild 1286 ✓#5…23.4 LTS patch. Now classified external (maintained elsewhere) — the mirror PR is green but nobody here merges it; see Addendum.
mailu—GREENnonebuild 483 ✓#3…A feature, not an upgrade: backupbot v2 backup labels (admin sqlite /data + imap mail /mail). App up-to-date at 2024.06.58.
bluesky-pds—UPTODATEnonepending · no CI run#4…App up-to-date (pds 0.4.5027). Routing-fix PR #4 (app→pds rename so caddy resolves the stack on the shared proxy) predates the cert outage and still has no !testme verdict — re-run now CI works.
cryptpad—UPTODATEnoneUp-to-date at 2026.5.1 (direct registry check — abra can't parse the version-… tag).
drone—UPTODATEnoneUp-to-date at 2.28.2.
mumble—UPTODATEnoneUp-to-date at v1.6.870-0.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

gitea 1.27.3 — 26-CVE security batch incl. Actions approval bypasses (high) · the git forge itself
1.27.2-rootless → 1.27.3-rootless fixes 26 CVEs — the deterministic scan's 24, plus CVE-2026-62925 (adjudicated FIXED from the vendor's patch note) and CVE-2026-70406 (named in the vendor security post, not yet in GHSA). Five are rated high per the vendor, four of those with GHSA advisories so far: CVE-2026-60010, -66877, -68957, -71184 — spanning fork-PR Actions approval bypasses (code execution where self-hosted runners are enabled), restricted-user data leaks, package-registry access control and token-scope enforcement. The count is a floor: sidecar advisory CVE-2025-68939 could not be judged and is unmeasured, not unaffected. postgres is deliberately held at 15 (a DB-major bump needs an operator dump/restore). !testme GREEN at build 1306 — merge, then abra recipe release gitea -z. The unrelated app.ini fix PR #4 (green at 1250) is also open.
keycloak 26.7.3 — 22 security fixes on the identity provider (high) · keycloak
26.7.2 → 26.7.3 closes 22 CVEs named in the vendor changelog: an unsigned signed-JWT assertion bypass (CVE-2026-16093), LDAP certificate hostname verification (CVE-2026-35563), an incomplete redirect_uri fix (CVE-2026-18209), FGAP/role authorization bypasses (CVE-2026-16105, -16106, -18570, -18571), user PII disclosure in GET /roles/{role}/users (CVE-2026-17059), raw reCAPTCHA secret exposure (CVE-2026-16104), and an incomplete fix of a path traversal (CVE-2026-19729), among others. Operators deploying from ≤26.7.1 additionally land critical CVE-2026-18963 (unauthenticated account takeover via reset-credentials bypass, fixed in 26.7.2 — already carried in main). Known 26.7.x watch-items, not blockers: admin-API cost growth with many realms (#51554) and post-upgrade high CPU (#51523). No migrations; mariadb 12.3 held. !testme GREEN at build 1307.
lasuite-meet — nginx 1.31.3 high batch + redis 8.10.1 security release (high) · now CI-verified
The v1.21.0 → v1.29.0 PR crosses nginx 1.31.2 → 1.31.4, picking up the three high nginx CVEs fixed in 1.31.3 (CVE-2026-42533, -56434, -60005) that last week's cert outage left unverified, plus redis 8.8.0 → 8.10.1 — a SECURITY release fixing CVE-2026-62356 (heap out-of-bounds write in CMSketch RDB loading) and several further flaws the vendor names without CVE ranges, so the count of 4 is a floor. livekit v1.13.6 rides along (its only default change is the H.264 baseline codec leaving the enabled list — standard clients unaffected). AUTO_MIGRATIONS handled the database. !testme GREEN at build 1311 — last week's blocked flag is cleared.
discourse 2026.7.2 — eight vendor security-fix groups, severities undisclosed · internet-facing
The 2026.7.1 → 2026.7.2 patch on the 2026.7 ESR line carries eight security-fix groups (18 SECURITY-tagged commits): stored XSS in video placeholders and email video titles, iframe allowlist / userinfo / wildcard fixes, embed-URL escaping in the footer, LIKE-metachar escaping on upload paths, hidden-post-revision reconstruction blocking, anonymous-cache-key partitioning, and more. Upstream publishes no CVE IDs for this release (advisory scan: 0; the one candidate, CVE-2025-53016, predates the window and was adjudicated already-fixed in 2026.7.1) — so the table's 0 means "no identified CVEs", not "no security content". Rails migrations auto-run on boot; no config changes. !testme GREEN at build 1303 (a duplicate trigger also resolved green at 1305).

What changed

1.27.2-rootless → 1.27.3-rootless, a pure security patch: 26 CVEs (see the bulletin) across Actions approval flows, restricted-user data exposure, package-registry access and token scopes; no config or migration changes. postgres deliberately held at 15 — the 16/17/18 major is an operator dump/restore step. Recommended release: abra recipe release gitea -z. Unrelated fix PR #4 (writable app.ini, green at build 1250) awaits its own decision.
26.7.2 → 26.7.3: 22 security fixes (JWT assertion bypass, LDAP hostname verification, redirect_uri and FGAP authz bypasses, PII disclosure — see the bulletin), no migrations, no KC_* env changes; mariadb 12.3 held. Fresh PR #8 — last week's #7 was closed unmerged after the survey mis-read the base (upstream main already carried 26.7.2); the verified window is 26.7.2 → 26.7.3. Watch-items: admin-API cost growth with many realms (#51554), post-upgrade CPU spikes (#51523). Release: abra recipe release keycloak -z.
v1.21.0 → v1.29.0 (app/backend/celery) + livekit v1.13.6, redis 8.8.0 → 8.10.1 (security release), nginx 1.31.2 → 1.31.4 (the 1.31.3 high batch — see the bulletin). Four upstream minors of features (lobby management on trusted rooms, media diagnostics telemetry, Redis KEYS → SCAN) with no breaking changes; migrations auto-ran clean. The base was re-verified against the force-synced mirror after the survey's v1.25.2 numbers turned out to be local-only checkout drift (now discarded).
10.11.22 → 11.7.10: off the 10.11 ESR line that ended 2026-08-15 onto the current 11.7 ESR (EOL 2027-05-15) — a vendor-supported ESR→ESR move with DB migrations on boot. 13 CVEs (all medium/low) land with it; postgres 15-alpine is held as a separate operator step. The PR preserves the pg_backup restore fix; PR #1 (the same fix standalone, green at 901) still needs a fold-or-merge decision. Release: abra recipe release mattermost-lts -x (major).
2026.7.1 → 2026.7.2, a security patch on the 2026.7 ESR line: eight security-fix groups (stored XSS in video placeholders, iframe allowlist fixes, embed-URL escaping — see the bulletin), one optional livestream_allowed_hosts site setting, and a reviewables performance index. No config changes; Rails db:migrate and the pg18 in-place path run automatically on boot. Re-verified GREEN now the cert is renewed (build 1303; a duplicate trigger also green at 1305). Release: abra recipe release discourse -z.
6.60.0-alpine → 6.61.0-alpine: emailable gift subscriptions + Portal gift-sub links, resilience fix for disconnected clients, email-analytics cursor and SQLite fetchMissing crash fixes; no breaking changes, no required migrations. PR #7 was extended past its stale 6.59.0 target — the earlier 6.45→6.59 window (nine CVEs, counted last week) already landed in main via upstream's own merges, so this extension carries no new CVEs. mysql held at 8.4 (Ghost supports MySQL 8 only). Release: abra recipe release ghost -y.
impress v5.4.1 → v5.5.0 across frontend/backend/celery/y-provider: skip-to-content link, new i18n locales, conditional server-to-server email notifications, presenter slide links; fixes for pins refresh, homepage redirect, CSPs and relative-url image export. AUTO_MIGRATIONS ran clean; no config changes. Release: abra recipe release lasuite-docs -y.
v0.21.0 → v0.21.2: two malware-analysis patches (re-analysis of already-scanned files; processing-slot exhaustion) plus scheduled reconciliation commands and admin abandon-actions. No migrations, no config changes. collabora deliberately held at 25.04 — the 26.04 image is shell-less and needs a service redesign (flagged to the maintainer in the PR); minio stays at its Docker Hub cap; onlyoffice already max. Release: abra recipe release lasuite-drive -z.
2.34.4 → 2.37.6, extended past last week's 2.37.3 target (2.37.5 was withdrawn upstream — no plain manifest; 2.37.6 is the newest tag). Two core bugfixes on top of the feature minor; TypeORM auto-migrations ran clean and the full Level 5/5 suite is green at build 1312. Note 2.37.x is still marked pre-release upstream — the stable line is 2.36.9; tracking the newest tag is the established precedent. Release: abra recipe release n8n -y.
synapse v1.157.1 → v1.159.0, MAS 1.23.0, mautrix-telegram v0.2608.0; nginx already at 1.31.4. Carry-over from 08-21, green at build 1298 — merge-ready; database majors deliberately held.
nginx 1.31.3 → 1.31.4 (feature/bugfix release: PROXY protocol v2 in stream/mail, gRPC/HTTP2 fixes); the high CVE batch was fixed in 1.31.3, which main already pins, so this adds no CVE fixes. Carry-over, green at build 1291 — merge-ready.
static-web-server → 2.44.0 (latest). Carry-over, green at build 1159 — merge-ready.
pgautoupgrade 16-alpine → 18-alpine — a DB-major bump handled in-place by pgautoupgrade; the app stays at 1.12.0 (latest). Carry-over, green at build 1302 — merge-ready.
7.0.4 → 7.1.0. Carry-over, green at build 1301 — merge-ready.
immich-server + machine-learning → v3.1.0, with the postgres pin matched to v3.1.0's released compose. Carry-over, green at build 1211 — merge-ready.
clickhouse → 23.4.6.25-alpine (23.4 LTS patch). Carry-over, green at build 1286 — but plausible is now classified external (maintained elsewhere), so this mirror PR needs a merge-or-close decision (see Addendum).
Not an upgrade: PR #3 adds backupbot v2 backup labels (admin sqlite /data + imap mail /mail), so the app's data becomes backupbot-covered. Green at build 483; the app itself is up-to-date at 2024.06.58.
A routing fix, not an upgrade: renames the main service app → pds so caddy resolves this stack on the shared proxy. Still no CI verdict (pending) — it predates the cert outage; re-run !testme now that CI works.